CVE-2026-86831

Source
https://cve.org/CVERecord?id=CVE-2026-86831
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86831.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86831
Related
  • GHSA-7xv7-8r3j-3j25
  • GHSA-gjc7-c7mx-x8f3
Published
2026-09-16T19:49:49Z
Modified
2026-09-18T03:48:35Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
Details

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.

To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-1289"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86831.json"
}
References

Affected packages

Git / github.com/aws/amazon-vpc-cni-k8s

Affected ranges

Type
GIT
Repo
https://github.com/aws/amazon-vpc-cni-k8s
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.0"
        },
        {
            "introduced": "1.14.0"
        },
        {
            "fixed": "1.22.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}
Type
GIT
Repo
https://github.com/aws/aws-network-policy-agent
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.1.0
v1.*
v1.0.0
v1.1.0
v1.12.0
v1.2.0
v1.2.1
v1.22.0
v1.22.1
v1.22.2
v1.22.3
v1.3.0
v1.4.0-rc1
v1.4.0-rc2
v1.5.0-rc1
v1.6.0-rc1
v1.6.4-rc1
v1.7.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86831.json"