PT-2026-70220 · Seaweedfs · Seaweedfs
CVE-2026-72920
·
Published
2026-08-11
·
Updated
2026-09-10
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SeaweedFS versions prior to 4.24
Description
The filer registers the SeaweedIdentityAccessManagement gRPC service without requiring authentication when the
jwt.filer signing.key is unset. This allows any client with access to the filer gRPC port to invoke IAM RPCs, including CreateUser(), CreateAccessKey(), and PutPolicy(), to generate credentials and obtain S3 administrative control.Recommendations
Update to version 4.24.
Set the
jwt.filer signing.key to ensure mandatory authentication for the gRPC service.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaweedfs