Affected versions:
smb-volume-release: All versions prior to v3.60.0
CF Deployment: All versions prior to v56.0.0
Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 01 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0 | |
| Title | Tenant-controlled comma smuggles arbitrary CIFS mount options | |
| Weaknesses | CWE-88 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-01T19:40:16.203Z
Reserved: 2026-04-16T02:19:16.427Z
Link: CVE-2026-41013
Updated: 2026-06-01T19:40:04.454Z
Status : Received
Published: 2026-06-01T19:16:39.887
Modified: 2026-06-01T21:16:43.947
Link: CVE-2026-41013
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:30:26Z