SeaweedFS Distributed Storage System Lacks Mandatory Authentication
CVE-2026-72920

9.8CRITICAL

Key Information:

Vendor

Seaweedfs

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72920?

SeaweedFS, a distributed storage system, suffers from a serious flaw where the SeaweedIdentityAccessManagement gRPC service is registered without mandatory authentication when the 'jwt.filer_signing.key' is not configured. This allows any client that has access to the filer gRPC port to execute critical IAM remote procedure calls, such as CreateUser and CreateAccessKey. Consequently, malicious users can potentially gain S3 administrative control over the storage system. This vulnerability is mitigated in versions 4.24 and later, which enforce stricter authentication requirements.

Affected Version(s)

seaweedfs < 4.24

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.