CVE-2026-41013 Details
Description
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0
A vulnerability exists in all versions of Cloud Foundry Diego Release prior to v56.0.0, specifically within the SMB volume handling of the smb-volume-release component, all versions prior to v3.60.0. This vulnerability allows low-privileged Cloud Foundry space developers to bypass input validation on CIFS mount options, injecting arbitrary options that could lead to privilege escalation and security control bypass on multi-tenant Diego cells. The issue arises from the SMB mount-option validation logic, where crafted mount options can evade the intended allowlist, which is meant to separate harmless SMB configurations from risky root filesystem operations on shared infrastructure.
Users are advised to upgrade to Cloud Foundry Deployment version 56.0.0 or greater, which includes smb-volume-release v3.60.0. As an immediate workaround, SMB volume mounting can be disabled for CF space developers, restricting SMB volume operations to platform operators only, auditing existing SMB mounts created by space developers, and implementing additional network-level controls around Diego cells.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cloudfoundry.org/blog/cve-2026-41013-tenant-controlled-comma-smuggles-arbitrary-cifs-mount-options/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |