PT-2026-70220 · Seaweedfs · Seaweedfs

CVE-2026-72920

·

Published

2026-08-11

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeaweedFS versions prior to 4.24
Description The filer registers the SeaweedIdentityAccessManagement gRPC service without requiring authentication when the jwt.filer signing.key is unset. This allows any client with access to the filer gRPC port to invoke IAM RPCs, including CreateUser(), CreateAccessKey(), and PutPolicy(), to generate credentials and obtain S3 administrative control.
Recommendations Update to version 4.24. Set the jwt.filer signing.key to ensure mandatory authentication for the gRPC service.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-72920
CVE-2026-72920
GHSA-2V6V-25FM-P4FG
GO-2026-6351

Affected Products

Seaweedfs