CVE-2026-41013: Tenant-controlled comma smuggles arbitrary CIFS mount options
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control bypass on multi-tenant Diego cells. Affected versions: smb-volume-release: All versions prior to v3.60.0 CF Deployment: All versions prior to v56.0.0
Metrics
- CVSS v3.1
- 8.1
- Severity
- HIGH
- Fixed in
- 3.60.0
- Affected Products
- 2
HarborGuard Analysis
Synopsis
An input validation bypass in CloudFoundry Foundation's diego-release (smb-volume-release and CF Deployment) allows a low-privileged CF space developer to inject arbitrary kernel CIFS mount options by smuggling extra values past the mount-option allowlist using comma characters. The vulnerability is reachable over the network and requires only a low-privilege account, with no victim interaction needed. Successful exploitation lets an attacker escalate privileges and bypass security controls on shared Diego cells, reading sensitive data and tampering with persisted state. Patched-image rebuilds at smb-volume-release 3.60.0 and CF Deployment 56.0.0 are available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-41013 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against images in customer registries, CI pipelines, and custom-built container images. Any image carrying a vulnerable version of smb-volume-release or CF Deployment will surface as a finding in the matching customer's scan results.
AvailableHarborGuard is capable of scoring this finding at CVSS 8.1 (HIGH) and weighting it against each customer's per-environment compliance policy to determine breach of threshold. Triage routing is available to direct the finding to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at smb-volume-release 3.60.0 and CF Deployment 56.0.0 is available on HarborGuard the moment an affected image is identified. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild at the fix version, run a regression test suite, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the CloudFoundry API or CF space endpoints over the network to submit a crafted SMB volume mount request.
- AuthenticationRequired
Any low-privilege CF space developer account is sufficient; no administrative credentials are needed.
- Victim interactionNot required
The attacker acts entirely through their own API calls and does not need another user to take any action.
- Attack complexityDetail
The exploit is reliable and condition-free; no race condition or specific memory layout is required to smuggle the comma-delimited mount options.
Blast Radius
- Reads sensitive files and credentials accessible to other tenants on the shared Diego cell by injecting mount options that bypass isolation controls.
- Modifies kernel-level CIFS mount behavior to redirect or tamper with shared volume data belonging to other CF applications on the same cell.
- Bypasses security controls enforced by the mount-option allowlist, enabling privilege escalation on the multi-tenant host.
- Does not directly crash the affected service (availability impact is rated None in the CVSS vector).
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-41013 is active against all customer registries and pipelines, with findings surfaced within minutes of the CVE entering upstream feeds. For environments running smb-volume-release below 3.60.0 or CF Deployment below 56.0.0, a patched-image rebuild at the respective fix versions is available. Where compliance policy permits, auto-remediation customers receive a rebuilt image, a regression-test run, and a PR opened against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Customers who have not yet enabled auto-remediation can use the HarborGuard findings dashboard to identify affected images and prioritize manual upgrades. Until upgraded, compensating controls such as network-policy restrictions limiting which principals can submit volume mount requests, and egress filtering on Diego cells, are worth considering to reduce the window of exposure.
Fix available
- CloudFoundry Foundation / smb-volume-release< 3.60.0 (from 0)
- CloudFoundry Foundation / CF Deployment< 56.0.0 (from 0)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N