AWS EKS Network Policy Agent <1.4: Pod ID Collision Policy Bypass
CVE-2026-86831 Published on September 16, 2026
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.
To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).
Vulnerability Analysis
CVE-2026-86831 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Validation of Unsafe Equivalence in Input
The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.
Products Associated with CVE-2026-86831
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-86831 are published in these products:
Affected Versions
aws-network-policy-agent:- Before 1.4.0 is affected.
- Version 1.14.0 and below 1.22.4 is affected.