Local Path ProvisionerApplication · Suse

CVE-2026-44543

HIGH · 8.7 CVSS v3.1 Published 2026-05-28
Fix available
A fix is available. Upgrade to 0.0.36 or later.
See remediation →
93/100
Remediation priority · Urgent
Remotely reachable Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The helperPod.yaml template is loaded by the provisioner and used to create HelperPods during PVC provisioning and cleanup operations. However, the template is not sufficiently validated before use. Security-sensitive fields such as securityContext.privileged, hostPath volumes, and Linux capabilities can be injected into the template. When a PVC operation triggers HelperPod creation, the provisioner creates the HelperPod using the attacker-controlled template. This can result in a privileged pod running on the target node with the host root filesystem mounted. This may allow the attacker to access sensitive host files, read ServiceAccount tokens from other pods on the same node, access other tenants' local-path volume data, or modify files on the host node. This vulnerability is fixed in 0.0.36.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

The local-path-provisioner loads a helperPod.yaml template from the local-path-config ConfigMap without sufficient validation. An attacker with permissions to edit this ConfigMap can inject security-sensitive fields (securityContext.privileged, hostPath volumes, Linux capabilities) into the template. When PVC provisioning or cleanup occurs, the provisioner creates a HelperPod using this attacker-controlled template, resulting in a privileged pod with host root filesystem access.

MitigationUpgrade rancher/local-path-provisioner to version 0.0.36 or later which includes template validation. Additionally, restrict RBAC permissions on the local-path-config ConfigMap to prevent untrusted users from editing it.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Local Path ProvisionerApplication
Affected:< 0.0.36

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Check the installed version of local-path-provisioner
    Run 'kubectl get deployment -n kube-system local-path-provisioner -o jsonpath={.spec.template.spec.containers[0].image}' or check your package manager for the installed version of local-path-provisioner
    Affected if The version is below 0.0.36
  2. Identify the namespace and ConfigMap containing the helperPod template
    Run 'kubectl get configmap -n kube-system local-path-config' to locate the ConfigMap that contains the helperPod.yaml template
    Affected if The ConfigMap exists and contains a helperPod.yaml template key
  3. Examine the helperPod.yaml template for injected security-sensitive fields
    Run 'kubectl get configmap -n kube-system local-path-config -o jsonpath={.data.helperPod\.yaml}' and inspect the template for presence of 'securityContext', 'privileged: true', 'hostPath' volumes, or 'capabilities' fields
    Affected if The template contains securityContext.privileged, hostPath volumes, or Linux capabilities that were not intentionally configured by the administrator
  4. Review RBAC permissions on the local-path-config ConfigMap
    Run 'kubectl auth can-i update configmaps/local-path-config -n kube-system' and check 'kubectl get rolebinding,clusterrolebinding -n kube-system -o yaml | grep -A5 local-path-config' to determine who can modify the ConfigMap
    Affected if Users or service accounts without administrator privileges can edit or update the ConfigMap

You are affected if the local-path-provisioner version is below 0.0.36 AND untrusted users can modify the local-path-config ConfigMap containing a helperPod.yaml template with injected privileged security settings.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 0.0.36 or later
Fixed in 0.0.36
Interim mitigation

Upgrade rancher/local-path-provisioner to version 0.0.36 or later which includes template validation. Additionally, restrict RBAC permissions on the local-path-config ConfigMap to prevent untrusted users from editing it.

Recommended fix High confidence

Local Path Provisioner >= 0.0.36

  1. Identify the current version of Local Path Provisioner deployed in the cluster
  2. Upgrade Local Path Provisioner to version 0.0.36 or later
  3. Verify the upgrade was successful by checking the deployed version
  4. Confirm the local-path-config ConfigMap in the local-path-storage namespace is not being manipulated with untrusted security-sensitive fields

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Local Path Provisioner Scoped from the published advisory
  • Consultation2.0 h
  • Implementation4.0 h
  • Testing4.0 h
  • Review / QA2.0 h
12.0 hours of engineering $2,080
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,328.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-44543 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-44543 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data