Affected versions:
smb-volume-release: All versions prior to v3.60.0
CF Deployment: All versions prior to v56.0.0
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudfoundry
Cloudfoundry cf-deployment Cloudfoundry smb-volume-release |
|
| Vendors & Products |
Cloudfoundry
Cloudfoundry cf-deployment Cloudfoundry smb-volume-release |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0 | |
| Title | Tenant-controlled comma smuggles arbitrary CIFS mount options | |
| Weaknesses | CWE-88 | |
| References |
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-04T17:36:02.891Z
Reserved: 2026-04-16T02:19:16.427Z
Link: CVE-2026-41013
Updated: 2026-06-01T19:40:04.454Z
Status : Awaiting Analysis
Published: 2026-06-01T19:16:39.887
Modified: 2026-06-02T14:01:54.893
Link: CVE-2026-41013
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:53:07Z