Executive Summary
In September 2026, Cloudflare disclosed a critical vulnerability in its Containers and Sandboxes service that allowed Workers Paid account holders to access residual data from other customers' containers on shared physical hosts. The flaw, reported by security researcher Oren Yomtov from Accomplish, stemmed from a misconfigured shared storage pool that skipped zeroing reused 64 KiB blocks. By writing only 4 KiB to unused regions, attackers could access up to 60 KiB of unwiped data from previous tenants, including SQLite databases, credentials, and application files. Researchers found exploitable residual data on 18 of 24 tested container placements across 20 of 22 nodes. This incident highlights the persistent challenges of maintaining tenant isolation in multi-tenant cloud environments, particularly as organizations increasingly rely on containerized workloads and serverless computing platforms for business-critical applications and data processing.
Why This Matters Now
Multi-tenant isolation failures are becoming more critical as organizations accelerate cloud adoption and containerization. This incident demonstrates how storage-level misconfigurations can bypass application-layer security controls, exposing sensitive customer data across tenant boundaries in ways that traditional perimeter defenses cannot prevent.
Attack Path Analysis
Attacker with Cloudflare Workers Paid account exploited cross-tenant container vulnerability by creating new containers and writing minimal data to trigger allocation of non-zeroed storage blocks containing residual customer data. The vulnerability allowed reading filesystem metadata, directory structures, database pages, and application data across tenant boundaries through storage block reuse exploitation.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker obtained legitimate Cloudflare Workers Paid account access and exploited cross-tenant container storage vulnerability by creating containers on shared infrastructure
MITRE ATT&CK® Techniques
Valid Accounts
Data from Cloud Storage Object
Credentials In Files
Escape to Host
Cloud Infrastructure Discovery
Stored Data Manipulation
Transfer Data to Cloud Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Primary Account Number Rendering and Data Retention
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.15
DORA – ICT Third-Party Risk Management
Control ID: Article 8
CISA ZTMM 2.0 – Data Categorization and Protection
Control ID: Data Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Cloud configuration vulnerabilities in containerized environments expose cross-tenant data leakage risks, compromising application security and customer data isolation boundaries.
Internet
Cloudflare's container cross-tenant flaw demonstrates critical cloud infrastructure vulnerabilities affecting web services, requiring enhanced multi-cloud visibility and zero trust segmentation.
Financial Services
Container isolation failures threaten sensitive financial data through residual storage exposure, violating PCI compliance requirements and enabling potential credential theft.
Health Care / Life Sciences
Cross-tenant container vulnerabilities expose patient data and medical records, violating HIPAA requirements and compromising healthcare application data integrity standards.
Sources
- Cloudflare fixes Containers cross-tenant flaw exposing customer datahttps://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/Verified
- Cloudflare Containers Cross-Tenant Vulnerability Disclosurehttps://blog.cloudflare.com/containers-cross-tenant-vulnerability/Verified
- Escaping the Cloudflare Sandbox - Accomplish Research Bloghttps://accomplish.ai/blog/escaping-the-cloudflare-sandbox/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this cross-tenant container vulnerability by constraining lateral movement between workloads and limiting systematic data access across shared infrastructure nodes.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely constrain the attacker's ability to freely create containers across shared infrastructure by applying workload-level security policies and identity verification requirements
Control: Zero Trust Segmentation
Mitigation: Segmentation policies would likely limit the attacker's ability to manipulate containers across tenant boundaries by enforcing strict workload isolation and reducing access to shared storage resources
Control: East-West Traffic Security
Mitigation: East-west security controls would likely constrain the attacker's systematic movement across infrastructure nodes by enforcing workload-to-workload communication policies and restricting cross-node container deployment patterns
Control: Multicloud Visibility & Control
Mitigation: Visibility and control mechanisms would likely detect and constrain systematic script execution patterns across multiple container instances, reducing the attacker's ability to orchestrate coordinated data discovery operations
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely constrain the attacker's ability to extract recovered data by monitoring and controlling outbound data flows from compromised containers across multiple infrastructure nodes
While cross-tenant data exposure occurred, Zero Trust controls would likely have reduced the overall scope of accessible customer data and limited the attacker's reach across infrastructure boundaries
Impact at a Glance
Affected Business Functions
- Cloud Application Hosting
- Containerized Workload Management
- Backend Service Operations
- Code Execution Environments
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of residual customer data including directory structures, SQLite databases, Chromium profiles, .env files, and credential files from previously deleted containers. The vulnerability affected Cloudflare Workers Paid plan customers using the Containers service, with researchers finding residual material on 18 of 24 container placements tested across 20 of 22 underlying nodes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with strict tenant isolation boundaries and namespace enforcement to prevent cross-tenant data access
- • Deploy Multicloud Visibility & Control to detect anomalous container creation patterns and repeated malformed storage allocation requests
- • Establish Egress Security & Policy Enforcement to monitor and control outbound data flows from containerized workloads
- • Enable Kubernetes Security (AKF) with pod-to-pod segmentation and namespace enforcement for container runtime protection
- • Activate Cloud Native Security Fabric (CNSF) for real-time inspection and distributed policy enforcement across shared infrastructure



