CPE
SeaweedFS versions prior to 4.24 contain an authentication bypass in the IAM gRPC service, allowing unauthenticated network actors to mint administrative S3 credentials and gain full control over object storage via CVE-2026-72920.