


Perceptive Security
SOC/SIEM Consultancy

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a …
Published:
26 augustus 2026 om 00:00:00
Alert date:
27 augustus 2026 om 01:02:07
Source:
nvd.nist.gov
Database & Storage, Identity & Access, Cloud & Virtualization
CVE-2026-77317 affects SeaweedFS, a distributed storage system, in versions 3.88 through 4.39. The SFTP server uses a literal string-prefix comparison to evaluate path permissions, allowing a user scoped to a specific path to also gain access to sibling paths sharing the same prefix. For example, a user with access to /tenants/alice would also inadvertently gain access to /tenants/alice-archive or /tenants/alice2. An authenticated low-privilege SFTP user can exploit this flaw to cross ACL boundaries and read or overwrite other tenants' files. The vulnerability does not require any special privileges beyond valid SFTP credentials. This constitutes a multi-tenant data isolation failure with potential for unauthorized data access and data tampering. The issue has been fixed in SeaweedFS version 4.40.
Technical details
Mitigation steps:
Affected products:
SeaweedFS 3.88 through 4.39
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-77317
https://github.com/seaweedfs/seaweedfs/commit/29981f8d24a62e9571962c4534fb23c48c00bae2
https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-fvpg-g364-j8vh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
