SCA: security update for github.com/rancher/local-path-provisioner (GHSA-7fxv-8wr2-mfc4)

high Tenable Cloud Security Plugin ID 442815

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node.
Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-
path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner.
The helperPod.yaml template is loaded by the provisioner and used to create HelperPods during PVC
provisioning and cleanup operations. However, the template is not sufficiently validated before use.
Security-sensitive fields such as securityContext.privileged, hostPath volumes, and Linux capabilities can
be injected into the template. When a PVC operation triggers HelperPod creation, the provisioner creates
the HelperPod using the attacker-controlled template. This can result in a privileged pod running on the
target node with the host root filesystem mounted. This may allow the attacker to access sensitive host
files, read ServiceAccount tokens from other pods on the same node, access other tenants' local-path
volume data, or modify files on the host node. This vulnerability is fixed in 0.0.36. (CVE-2026-44543)

Solution

Update the github.com/rancher/local-path-provisioner library and its related packages to version 0.0.36 or later.

See Also

https://github.com/advisories/GHSA-7fxv-8wr2-mfc4

Plugin Details

Severity: High

ID: 442815

Version: Revision 1.2

Type: Local

Family: SCA Checks

Published: 6/9/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.8

Percentile: 57.59

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.7

Temporal Score: 5.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:N

CVSS Score Source: CVE-2026-44543

CVSS v3

Risk Factor: High

Base Score: 8.7

Temporal Score: 7.6

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/11/2026

Vulnerability Publication Date: 5/11/2026

Reference Information

CVE: CVE-2026-44543