PT-2026-82323 · Seaweedfs · Seaweedfs

·

CVE-2026-77298

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SeaweedFS versions prior to 4.40
Description The S3 API accepts an external OIDC JWT (OpenID Connect JSON Web Token) sent directly in the Authorization header and maps it to an IAM role without enforcing the trust policy of that role. While the standard STS AssumeRoleWithWebIdentity() path correctly rejects tokens when the trust policy does not trust the federated provider, the direct S3 bearer path only validates the token itself. This allows a valid OIDC user to bypass trust policy restrictions and obtain S3 access, including the ability to read, write, and delete objects, by presenting the raw OIDC JWT directly to the S3 API.
Recommendations Update to version 4.40.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-77298
CVE-2026-77298
GHSA-757H-CM9X-WPRG

Affected Products

Seaweedfs