CVE-2026-41013
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2026
Last modified:
22/07/2026
Description
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells.<br />
<br />
Affected versions:<br />
smb-volume-release: All versions prior to v3.60.0<br />
CF Deployment: All versions prior to v56.0.0
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



