Unauthenticated Remote Code Execution in SeaweedFS Distributed Storage System
CVE-2026-73080
9.3CRITICAL
What is CVE-2026-73080?
SeaweedFS, a distributed storage system, suffers from a vulnerability in the VolumeServer.FetchAndWriteNeedle function. Prior to version 4.24, this function allows unauthenticated attackers to access the gRPC port of the volume server. This flaw permits malicious users to send requests to arbitrary endpoints, including local and cloud metadata addresses, potentially exposing sensitive information such as instance metadata and IAM credentials. The lack of proper authentication and target validation can lead to significant data breaches, particularly in cloud environments. Users are advised to upgrade to version 4.24 to mitigate this risk.
Affected Version(s)
seaweedfs < 4.24
