Authorization Bypass Vulnerability in SeaweedFS Distributed Storage System
CVE-2026-77298
8.7HIGH
What is CVE-2026-77298?
In versions up to 4.39 of SeaweedFS, an authorization bypass vulnerability exists within the S3 API. The system improperly processes external OIDC JWT tokens sent in the Authorization header, allowing a federated user to bypass role trust policies. This flaw enables users to gain unauthorized access to S3 permissions—including object read, write, and delete operations—by presenting a valid OIDC token directly to the API, instead of utilizing the standard STS AssumeRoleWithWebIdentity path. This vulnerability has been addressed in version 4.40.
Affected Version(s)
seaweedfs < 4.40
