CVE-2026-72920Critical· 9.8▾ MidnightSeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the f…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/seaweedfs/seaweedfs < 0.0.0-20260512171108-5e8f99f40a8aPatched in:
github.com/seaweedfs/seaweedfs 0.0.0-20260512171108-5e8f99f40a8aConnected by shared product, vendor, weakness, or advisory.
CVE-2026-72921High· 8.1SeaweedFS is a distributed storage system
CVE-2026-73080Critical· 9.3SeaweedFS is a distributed storage system
CVE-2026-55873Medium· 4.3SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
CVE-2026-54917HighSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2019-1895Critical· 9.8A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative …