Authentication Bypass in Alluxio's S3 REST Proxy
CVE-2026-79787

9.3CRITICAL

Key Information:

Vendor

Alluxio

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79787?

The S3 REST proxy in Alluxio is susceptible to an authentication bypass due to improper verification of AWS Signature Version 4 signatures in its default configuration. This vulnerability allows unauthenticated attackers to spoof user identities, enabling them to extract usernames from unsigned Authorization headers. By impersonating any user, including service accounts, attackers can gain unauthorized access to read, write, and delete sensitive data, posing significant risks to data integrity and security.

Affected Version(s)

alluxio 0 <= 2.9.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.