PT-2026-56467 · Seaweedfs · Seaweedfs

·

CVE-2026-55873

·

Published

2026-07-08

·

Updated

2026-09-08

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SeaweedFS versions 4.08 through 4.33
Description Requests signed with the SigV4 service s3tables are routed to the S3Tables management API. In this process, authorization collapses account-less S3 identities into a shared admin account and fails open. This allows an authenticated low-privileged S3 user to enumerate Amazon Resource Names (ARNs) and table bucket names owned by the administrator.
Recommendations Update SeaweedFS to version 4.34.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-55873
CVE-2026-55873
GHSA-HGPF-8634-G44C
GO-2026-6329
OPENSUSE-SU-2026:21812-1

Affected Products

Seaweedfs