CVE-2026-55873 Details
Description
SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
A vulnerability in SeaweedFS versions 4.08 prior to 4.34 allows low-privileged S3 users to improperly access S3Tables management features. This issue arises because account-less S3 identities are defaulted to the shared admin account, enabling these users to enumerate administrator-owned table buckets and their associated ARNs. The vulnerability is present in the S3Tables management API, which was introduced in SeaweedFS version 4.08. The same flaw affects the Iceberg REST catalog, which relies on the S3Tables management API.
Users can upgrade to SeaweedFS version 4.34 or later, where this vulnerability has been fixed. Instructions for downloading the latest version can be found on the SeaweedFS GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 8, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/seaweedfs/seaweedfs/commit/b13463880c1fa62e255c058a9228b63cc95b4b36 | [email protected] | Source CodeVendor |
| https://github.com/seaweedfs/seaweedfs/pull/9961 | [email protected] | Source CodeVendor |
| https://github.com/seaweedfs/seaweedfs/releases/tag/4.34 | [email protected] | Release NotesVendor |
| https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-hgpf-8634-g44c | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SeaweedFS | >= 4.08, < 4.34 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2026 | New CVE Received | [email protected] |
Volerion