Threat Advisory

SeaweedFS Unauthenticated Filer IAM gRPC Service Grants S3 Administrative Control

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in seaweedfs < 0.0.0-20260512171108-5e8f99f40a8a and < 0.0.0-20260512171048-05ed5c9ae8a2.

CVE-2026-72920 (CVSS 9.8 — Severity): An unauthenticated filer IAM gRPC service grants S3 administrative control, allowing any client to invoke IAM RPCs and mint credentials for S3 administrative privileges.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in seaweedfs < 0.0.0-20260512171108-5e8f99f40a8a and < 0.0.0-20260512171048-05ed5c9ae8a2.

CVE-2026-72920 (CVSS 9.8 — Severity): An unauthenticated filer IAM gRPC service grants S3 administrative control, allowing any client to invoke IAM RPCs and mint credentials for S3 administrative privileges.[emaillocker id="1283"]

CVE-2026-72921 (CVSS 8.1 — Severity): When a filer JWT restricts a token to a set of path prefixes via allowed_prefixes, the authorization check uses a literal byte-prefix match, allowing cross-tenant access to sibling paths.

These vulnerabilities collectively present a high risk to administrators who manage SeaweedFS deployments.

RECOMMENDATION:

We recommend you to update SeaweedFS to version 0.0.0-20260512171108-5e8f99f40a8a or 0.0.0-20260512171048-05ed5c9ae8a2.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu