
Path traversal in SMB CSI driver risks destructive SMB cleanup
CVE-2026-3865 discloses a Kubernetes `smb.csi.k8s.io` path traversal where PersistentVolume creators can trigger deletion/modification of unintended SMB-export directories; fixed in v1.20.1.





