Path Traversal Vulnerability in lakeFS Open-Source Tool by Treeverse
CVE-2026-26187

8.1HIGH

Key Information:

Vendor

Treeverse

Status
Vendor
CVE Published:
13 February 2026

What is CVE-2026-26187?

The lakeFS tool, developed by Treeverse, presents a path traversal vulnerability that impacts its functionality. Authenticated users could exploit this issue to access files beyond their specified storage bounds. In versions before 1.77.0, the local block adapter failed to enforce sufficient path validation, only checking for prefixes without ensuring a separation. This flaw permits access to sibling directories with similar naming, leading to unauthorized file exposure. Moreover, the system's path verification inadequately restricted object identifiers to their respective storage namespaces, allowing attackers to manipulate path traversal sequences to gain access to files elsewhere. This vulnerability was addressed and resolved in version 1.77.0.

Affected Version(s)

lakeFS < 1.77.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.