CVE-2026-85781 affects the Amazon EFS CSI Driver before version v3.4.1. The vulnerability stems from unverified ownership of storage access points in the volume deletion component. An authenticated Kubernetes user with PersistentVolume creation privileges can exploit this flaw to cause recursive deletion of directories on EFS filesystems they are not authorized to access. The attack vector involves crafting a malicious PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. This constitutes a privilege escalation and unauthorized data destruction risk within Kubernetes environments using Amazon EFS. The vulnerability is classified as high severity given the potential for irreversible data loss. AWS has issued a security bulletin and released a patched version. Users are strongly advised to upgrade to v3.4.1 immediately to remediate the issue.