CVE-2026-54917

CRITICAL LAB

SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-54917. PoCs published by BiiTts.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-54917, a path traversal vulnerability in SeaweedFS S3 gateway (<4.30) allowing cross-bucket unauthorized access via crafted `..` segments in object keys. The exploit demonstrates both read and write operations across buckets using SigV4-signed requests with traversal variants.

Description

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.

Exploits (1)

github WORKING POC
by BiiTts · pythonpoc
https://github.com/BiiTts/CVE-2026-54917-SeaweedFS-Cross-Bucket-Traversal

This repository contains a functional exploit for CVE-2026-54917, a path traversal vulnerability in SeaweedFS S3 gateway (<4.30) allowing cross-bucket unauthorized access via crafted `..` segments in object keys. The exploit demonstrates both read and write operations across buckets using SigV4-signed requests with traversal variants.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SeaweedFS versions before 4.30 (S3 gateway component)
Auth required
Prerequisites: Valid S3 credentials for at least one bucket · Network access to SeaweedFS S3 gateway endpoint · Target bucket must exist and contain accessible objects
mistral-large-3 · analyzed Aug 05, 2026 Full analysis →

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/pull/9687

Scores

CVSS v3 10.0
EPSS 0.0038
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull chrislusf/seaweedfs:4.29

Details

CWE
CWE-22
Status published
Products (2)
seaweedfs/seaweedfs < 4.30 (2 CPE variants)
seaweedfs/seaweedfs 0 - 0.0.0-20260526080459-dd1b4287899eGo
Published Jun 25, 2026
Tracked Since Jun 26, 2026