


Perceptive Security
SOC/SIEM Consultancy

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive…
Published:
1 juli 2026 om 22:00:00
Alert date:
2 juli 2026 om 21:02:59
Source:
nvd.nist.gov
Cloud & Virtualization, Database & Storage, Identity & Access
JuiceFS versions through 1.3.1 contain an authentication bypass vulnerability (CVE-2026-59092) fixed in commit a46979c. The flaw stems from improper handler registration on the shared http.DefaultServeMux, allowing unauthenticated remote attackers to access sensitive debug and metrics endpoints. Attackers can exploit the /debug/pprof/cmdline endpoint to retrieve the process command line, which may contain metadata engine connection strings with database credentials. This grants full read/write access to filesystem metadata. Additional pprof handlers expose internal state information, and profiling handlers can be abused to cause denial of service. The vulnerability poses a significant risk to deployments exposing these endpoints to untrusted networks.
Technical details
Mitigation steps:
Affected products:
JuiceFS 1.3.1 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59092
https://github.com/juicedata/juicefs/commit/a46979cdd4082217081ee99b931ddc53d038e47a
https://github.com/juicedata/juicefs/issues/7213
https://github.com/juicedata/juicefs/pull/7214
https://www.vulncheck.com/advisories/juicefs-authentication-bypass-via-pprof-and-metrics-endpoints
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
