CVE-2026-72921High· 8.1▾ TwilightSeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/seaweedfs/seaweedfs < 0.0.0-20260512171048-05ed5c9ae8a2Patched in:
github.com/seaweedfs/seaweedfs 0.0.0-20260512171048-05ed5c9ae8a2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-72920Critical· 9.8SeaweedFS is a distributed storage system
CVE-2026-55873Medium· 4.3SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
CVE-2026-73080Critical· 9.3SeaweedFS is a distributed storage system
CVE-2026-54917HighSeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
CVE-2020-3578Medium· 5.3A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…
CVE-2024-6593Critical· 9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…