Multiple security vulnerabilities have been identified in seaweedfs < 0.0.0-20260512171108-5e8f99f40a8a and < 0.0.0-20260512171048-05ed5c9ae8a2.
CVE-2026-72920 (CVSS 9.8 — Severity): An unauthenticated filer IAM gRPC service grants S3 administrative control, allowing any client to invoke IAM RPCs and mint credentials for S3 administrative privileges.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in seaweedfs < 0.0.0-20260512171108-5e8f99f40a8a and < 0.0.0-20260512171048-05ed5c9ae8a2.
CVE-2026-72920 (CVSS 9.8 — Severity): An unauthenticated filer IAM gRPC service grants S3 administrative control, allowing any client to invoke IAM RPCs and mint credentials for S3 administrative privileges.[emaillocker id="1283"]
CVE-2026-72921 (CVSS 8.1 — Severity): When a filer JWT restricts a token to a set of path prefixes via allowed_prefixes, the authorization check uses a literal byte-prefix match, allowing cross-tenant access to sibling paths.
These vulnerabilities collectively present a high risk to administrators who manage SeaweedFS deployments.
We recommend you to update SeaweedFS to version 0.0.0-20260512171108-5e8f99f40a8a or 0.0.0-20260512171048-05ed5c9ae8a2.
The following reports contain further technical details:
[/emaillocker]