Threat Advisory

SeaweedFS Path Traversal Allows Cross-Bucket Access

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54917 is a high-severity vulnerability affecting SeaweedFS versions < 0.0.0-20260526080459-dd1b4287899e, allowing cross-bucket access through path traversal. All releases prior to 4.30 are affected, as an attacker can exploit this flaw by sending a request with a URL containing a `..` segment, which survives routing and allows access to objects in other buckets. This issue breaks tenant isolation and enables direct cross-bucket read and write operations when authentication is disabled. With authentication enabled, it causes an authorization confused-deputy attack, allowing a principal authorized for one bucket to reach objects in another bucket they have no grant for. The vulnerability can be exploited via the environment template management API or by accessing the affected components directly. This flaw has significant business impact as it compromises data integrity and confidentiality across multiple buckets.

RECOMMENDATION:

We recommend you to upgrade SeaweedFS to version 0.0.0-20260526080459-dd1b4287899e.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-54917 is a high-severity vulnerability affecting SeaweedFS versions < 0.0.0-20260526080459-dd1b4287899e, allowing cross-bucket access through path traversal. All releases prior to 4.30 are affected, as an attacker can exploit this flaw by sending a request with a URL containing a `..` segment, which survives routing and allows access to objects in other buckets. This issue breaks tenant isolation and enables direct cross-bucket read and write operations when authentication is disabled. With authentication enabled, it causes an authorization confused-deputy attack, allowing a principal authorized for one bucket to reach objects in another bucket they have no grant for. The vulnerability can be exploited via the environment template management API or by accessing the affected components directly. This flaw has significant business impact as it compromises data integrity and confidentiality across multiple buckets.

RECOMMENDATION:

We recommend you to upgrade SeaweedFS to version 0.0.0-20260526080459-dd1b4287899e.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu