{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aseaweedfsseaweedfs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-72920"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SeaweedFS (\u003c 4.24)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SeaweedFS"],"content_html":"\u003cp\u003eSeaweedFS versions prior to 4.24 are vulnerable to an authentication bypass vulnerability (CVE-2026-72920) within the filer IAM gRPC service. The SeaweedIdentityAccessManagement service was registered without authentication requirements, meaning any client with network access to the filer gRPC port could invoke administrative RPC methods such as CreateUser, CreateAccessKey, and PutUserPolicy. This vulnerability persists even if JWT signing keys are configured or if mTLS is in use, as the service lacked specific internal authorization checks. By exploiting this, an attacker can create new administrative users and access keys, granting themselves full read and write control over all S3-compatible object storage managed by the affected filer. This represents a critical risk to data confidentiality, integrity, and availability. Operators must upgrade to version 4.24, which mandates that all IAM RPCs utilize a Bearer token signed by the filer admin signing key.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable SeaweedFS filer gRPC ports (typically port 8888).\u003c/li\u003e\n\u003cli\u003eAttacker establishes a connection to the gRPC service without providing valid credentials.\u003c/li\u003e\n\u003cli\u003eAttacker calls the SeaweedIdentityAccessManagement CreateUser RPC method to register a new identity.\u003c/li\u003e\n\u003cli\u003eAttacker calls the CreateAccessKey RPC method to generate high-privileged credentials for the new user.\u003c/li\u003e\n\u003cli\u003eAttacker calls the PutUserPolicy RPC method to elevate the new identity to S3 administrator status.\u003c/li\u003e\n\u003cli\u003eAttacker uses the newly minted credentials to authenticate via S3 API calls.\u003c/li\u003e\n\u003cli\u003eAttacker performs unauthorized exfiltration or manipulation of data stored within the SeaweedFS filer.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full administrative compromise of the object storage service. Attackers can gain unrestricted access to the contents of all buckets, modify stored objects, or delete data entirely. This vulnerability affects any deployment where the filer gRPC port is exposed to untrusted network segments, impacting enterprise users relying on SeaweedFS for distributed storage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all SeaweedFS instances to version 4.24 immediately to address CVE-2026-72920.\u003c/li\u003e\n\u003cli\u003eApply network-level access control lists (ACLs) to restrict access to the SeaweedFS gRPC port to trusted management subnets only.\u003c/li\u003e\n\u003cli\u003eConfigure a secure jwt.filer_signing.key in the security.toml file as mandated by the patch to ensure all administrative gRPC operations require valid tokens.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T18:03:20Z","date_published":"2026-09-02T18:03:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-seaweedfs-iam-auth-bypass/","summary":"SeaweedFS versions prior to 4.24 contain an authentication bypass in the IAM gRPC service, allowing unauthenticated network actors to mint administrative S3 credentials and gain full control over object storage via CVE-2026-72920.","title":"SeaweedFS Unauthenticated IAM gRPC Service Authentication Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-seaweedfs-iam-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}