PT-2026-53930 · Seaweedfs · Seaweedfs

·

CVE-2026-58372

·

Published

2026-06-30

·

Updated

2026-08-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeaweedFS versions prior to 4.34
Description A path traversal issue exists in the S3 gateway DeleteMultipleObjectsHandler. Authenticated S3 principals with write access to one bucket can delete arbitrary objects in buckets belonging to other tenants. This occurs when object keys containing ../ sequences are supplied in the DeleteObjects XML request body. The flaw stems from a confused deputy condition where the validateRequestPath middleware only inspects URL-captured path variables and ignores request-body keys, allowing the filer path to resolve deletions outside the authorized bucket.
Recommendations Update SeaweedFS to version 4.34 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-54917
CVE-2026-58372
GHSA-W62W-66V9-VVGV
GO-2026-6221

Affected Products

Seaweedfs