PT-2026-82324 · Seaweedfs · Seaweedfs
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SeaweedFS versions 3.88 through 4.39
Description
The SFTP server evaluates configured path permissions using a literal string-prefix comparison instead of requiring a path-component boundary. This allows an authenticated low-privilege user scoped to a specific path to access sibling paths that begin with the same characters. For example, a user with access to
/tenants/alice could potentially access /tenants/alice-archive or /tenants/alice2. This flaw enables a user to bypass Access Control List (ACL) boundaries to read or overwrite files belonging to other tenants.Recommendations
Update to version 4.40.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seaweedfs