Search/CVE-2026-86831
CVE — High

CVE-2026-86831

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions. To remediate this issue, users should upgrade to Amazon EKS Network Policy Agent 1.4.0 or later and Amazon VPC CNI Managed Add-on v1.22.4 or later (which includes Network Policy Agent v1.4.0).

CVSS v3.1
8.7 HIGH
EPSS
0.46%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
1
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityNONE
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Connections
2 relationships
Timeline
disclosure → media coverage
Sep 16, 2026
aws.amazon.com reports: CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
Sep 16, 2026
Disclosure — published as a CVE record.