S3 Permissions Vulnerability in SeaweedFS Distributed Storage by SeaweedFS
CVE-2026-77611

7.1HIGH

Key Information:

Vendor

Seaweedfs

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-77611?

In SeaweedFS, a distributed storage system, an issue arises in versions prior to 4.40 where an authenticated S3 user can inadvertently overwrite files outside their permission scope. By utilizing the PutObjectAcl command on an accessible key, the request is misauthorized. Consequently, this allows changes meant for protected items to instead affect the bucket root. This misconfiguration can lead to significant data integrity issues, as the entire entry—including existing content, metadata, and access control lists (ACLs)—is overwritten with the details of the scoped object instead of modifying just the ACL metadata. Users are encouraged to upgrade to version 4.40 to mitigate this risk.

Affected Version(s)

seaweedfs < 4.40

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.