S3 Permissions Vulnerability in SeaweedFS Distributed Storage by SeaweedFS
CVE-2026-77611
7.1HIGH
What is CVE-2026-77611?
In SeaweedFS, a distributed storage system, an issue arises in versions prior to 4.40 where an authenticated S3 user can inadvertently overwrite files outside their permission scope. By utilizing the PutObjectAcl command on an accessible key, the request is misauthorized. Consequently, this allows changes meant for protected items to instead affect the bucket root. This misconfiguration can lead to significant data integrity issues, as the entire entry—including existing content, metadata, and access control lists (ACLs)—is overwritten with the details of the scoped object instead of modifying just the ACL metadata. Users are encouraged to upgrade to version 4.40 to mitigate this risk.
Affected Version(s)
seaweedfs < 4.40
