PT-2026-82324 · Seaweedfs · Seaweedfs

·

CVE-2026-77317

·

Published

2026-08-26

·

Updated

2026-09-02

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SeaweedFS versions 3.88 through 4.39
Description The SFTP server evaluates configured path permissions using a literal string-prefix comparison instead of requiring a path-component boundary. This allows an authenticated low-privilege user scoped to a specific path to access sibling paths that begin with the same characters. For example, a user with access to /tenants/alice could potentially access /tenants/alice-archive or /tenants/alice2. This flaw enables a user to bypass Access Control List (ACL) boundaries to read or overwrite files belonging to other tenants.
Recommendations Update to version 4.40.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-SEAWEEDFS-2026-77317
CVE-2026-77317
GHSA-FVPG-G364-J8VH

Affected Products

Seaweedfs