PT-2026-82323 · Seaweedfs · Seaweedfs
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SeaweedFS versions prior to 4.40
Description
The S3 API accepts an external OIDC JWT (OpenID Connect JSON Web Token) sent directly in the
Authorization header and maps it to an IAM role without enforcing the trust policy of that role. While the standard STS AssumeRoleWithWebIdentity() path correctly rejects tokens when the trust policy does not trust the federated provider, the direct S3 bearer path only validates the token itself. This allows a valid OIDC user to bypass trust policy restrictions and obtain S3 access, including the ability to read, write, and delete objects, by presenting the raw OIDC JWT directly to the S3 API.Recommendations
Update to version 4.40.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaweedfs