SeaweedFS Distributed Storage System Lacks Mandatory Authentication
CVE-2026-72920
9.8CRITICAL
What is CVE-2026-72920?
SeaweedFS, a distributed storage system, suffers from a serious flaw where the SeaweedIdentityAccessManagement gRPC service is registered without mandatory authentication when the 'jwt.filer_signing.key' is not configured. This allows any client that has access to the filer gRPC port to execute critical IAM remote procedure calls, such as CreateUser and CreateAccessKey. Consequently, malicious users can potentially gain S3 administrative control over the storage system. This vulnerability is mitigated in versions 4.24 and later, which enforce stricter authentication requirements.
Affected Version(s)
seaweedfs < 4.24
