Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
Summary
| CVE | CVE-2026-86831 |
|---|---|
| State | PUBLISHED |
| Assigner | AMZN |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 20:17:36 UTC |
| Updated | 2026-09-17 17:16:51 UTC |
| Description | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions. To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0). |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from ff89ba41-3aa1-4d27-914a-91399e9639e5
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-1289 | CWE-1289 CWE-1289 Improper validation of unsafe equivalence in input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
| 3.1 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | Secondary | 8.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 8.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | AWS | Aws-network-policy-agent | affected 1.4.0 custom | Not specified |
| CNA | AWS | Amazon-vpc-cni-k8s | affected 1.14.0 1.22.4 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/aws/aws-network-policy-agent/security/advisories/GHSA-7xv7-8r... | ff89ba41-3aa1-4d27-914a-91399e9639e5 | github.com | |
| github.com/aws/aws-network-policy-agent/releases/tag/v1.4.0 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | github.com | |
| github.com/aws/amazon-vpc-cni-k8s/releases/tag/v1.22.4 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | github.com | |
| github.com/aws/amazon-vpc-cni-k8s/security/advisories/GHSA-gjc7-c7mx-x8f3 | ff89ba41-3aa1-4d27-914a-91399e9639e5 | github.com | |
| staging.prod.website.marketing.aws.dev/security/security-bulletins/2026-113-aws | ff89ba41-3aa1-4d27-914a-91399e9639e5 | staging.prod.website.marketing.aws.dev | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.