{"id":"CVE-2026-58372","title":"SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' bucke…","summary":"SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' bucke…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-22"],"vendor":"seaweedfs","product":"seaweedfs","affected":["seaweedfs < 4.34"],"published":"2026-06-30","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:23.057","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-58372","references":[{"url":"https://github.com/geo-chen/oss/blob/main/seaweedfs.md","label":"disclosure@vulncheck.com"},{"url":"https://github.com/seaweedfs/seaweedfs/commit/0345658ea8e7c6a3948ad190634b00866ec244c9","label":"disclosure@vulncheck.com"},{"url":"https://github.com/seaweedfs/seaweedfs/pull/9931","label":"disclosure@vulncheck.com"},{"url":"https://github.com/seaweedfs/seaweedfs/releases/tag/4.34","label":"disclosure@vulncheck.com"},{"url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/seaweedfs-cross-bucket-object-deletion-via-deleteobjects-request-body-keys","label":"disclosure@vulncheck.com"},{"url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-06-30T17:32:33.732751Z"},"epss":0.01119,"epssPercentile":0.65112,"ingestedAt":"2026-10-08T16:52:14.693Z","slug":"CVE-2026-58372","body":"## Overview\n\nSeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in the DeleteObjects XML request body. Attackers can bypass authorization controls through a confused deputy condition, as the validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys, allowing the filer path to collapse directory traversal sequences and resolve deletions outside the authorized bucket.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}