CVE-2026-58372
HIGHSeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
Title source: cnaDescription
SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in the DeleteObjects XML request body. Attackers can bypass authorization controls through a confused deputy condition, as the validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys, allowing the filer path to collapse directory traversal sequences and resolve deletions outside the authorized bucket.
References (6)
Core 6
Core References
Related, Issue Tracking related
issue-tracking
Fix PR
https://github.com/seaweedfs/seaweedfs/pull/9931
Patch patch
Fix Commit
https://github.com/seaweedfs/seaweedfs/commit/0345658ea8e7c6a3948ad190634b00866ec244c9
Prior advisory (CVE-2026-54917) - incompletely fixed
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/seaweedfs.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/seaweedfs-cross-bucket-object-deletion-via-deleteobjects-request-body-keys
Scores
CVSS v3
8.1
EPSS
0.0077
EPSS Percentile
51.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (1)
seaweedfs/seaweedfs
< 4.34
Published
Jun 30, 2026
Tracked Since
Jun 30, 2026