PT-2026-82771 · Ceph · Ceph

·

CVE-2026-54330

·

Published

2026-08-21

·

Updated

2026-09-02

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Ceph versions prior to 20.2.4 Ceph versions prior to 19.2.6
Description The Ceph Object Gateway (RGW) SigV4 handler fails to reject requests containing x-amz-* headers that are not included in the signed header set. While AWS S3 requires all x-amz-* headers in a SigV4 request to be signed, RGW only validates headers listed in X-Amz-SignedHeaders and ignores additional unsigned ones, allowing them to take effect. An attacker with a presigned PUT URL can attach arbitrary unsigned x-amz-* headers to escalate privileges and gain capabilities beyond what the signer intended.
Recommendations Update to version 20.2.4 or later. Update to version 19.2.6 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98340
BIT-CEPH-2026-54330
CVE-2026-54330
ECHO-BA60-36E6-9BCF
GHSA-RMJQ-FFRM-J6VJ

Affected Products

Ceph