Authentication Bypass in Alluxio's S3 REST Proxy
CVE-2026-79787
9.3CRITICAL
What is CVE-2026-79787?
The S3 REST proxy in Alluxio is susceptible to an authentication bypass due to improper verification of AWS Signature Version 4 signatures in its default configuration. This vulnerability allows unauthenticated attackers to spoof user identities, enabling them to extract usernames from unsigned Authorization headers. By impersonating any user, including service accounts, attackers can gain unauthorized access to read, write, and delete sensitive data, posing significant risks to data integrity and security.
Affected Version(s)
alluxio 0 <= 2.9.5
