CVE-2026-55873
MEDIUMSeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Title source: cnaDescription
SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-hgpf-8634-g44c
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/pull/9961
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/commit/b13463880c1fa62e255c058a9228b63cc95b4b36
X_Refsource_Misc x_refsource_misc
https://github.com/seaweedfs/seaweedfs/releases/tag/4.34
Scores
CVSS v3
4.3
EPSS
0.0020
EPSS Percentile
10.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (1)
seaweedfs/seaweedfs
>= 4.08, < 4.34
Published
Jul 08, 2026
Tracked Since
Jul 08, 2026