top of page
perceptive_background_267k.jpg

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a …

Published:

26 augustus 2026 om 00:00:00

Alert date:

27 augustus 2026 om 01:02:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Identity & Access, Cloud & Virtualization

CVE-2026-77317 affects SeaweedFS, a distributed storage system, in versions 3.88 through 4.39. The SFTP server uses a literal string-prefix comparison to evaluate path permissions, allowing a user scoped to a specific path to also gain access to sibling paths sharing the same prefix. For example, a user with access to /tenants/alice would also inadvertently gain access to /tenants/alice-archive or /tenants/alice2. An authenticated low-privilege SFTP user can exploit this flaw to cross ACL boundaries and read or overwrite other tenants' files. The vulnerability does not require any special privileges beyond valid SFTP credentials. This constitutes a multi-tenant data isolation failure with potential for unauthorized data access and data tampering. The issue has been fixed in SeaweedFS version 4.40.

Technical details

Mitigation steps:

Affected products:

SeaweedFS 3.88 through 4.39

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page