{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/noobaa-core/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:noobaa-core:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-94368"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["noobaa-core"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA vulnerability (CVE-2026-94368) has been identified in the signature verification logic of the noobaa-core component, which powers the NooBaa Multicloud Object Gateway. The flaw specifically affects how the service processes S3 presigned URLs using the Signature Version 4 (SigV4) protocol. When the gateway receives a request, it improperly handles unsigned x-amz- headers by silently dropping them from the signature calculation process rather than rejecting the request.\u003c/p\u003e\n\u003cp\u003eAn attacker holding a legitimate presigned PUT URL can exploit this by injecting an unsigned x-amz-copy-source header into the request. Because the server excludes this header from verification, the request remains valid, enabling the attacker to transform a standard upload request into a CopyObject operation. This allows an authenticated attacker to read and copy sensitive data to which the original presigned URL owner has access, potentially exposing objects across the entire storage system managed by the gateway. Defenders should prioritize patching noobaa-core and auditing S3 interaction logs for anomalous usage of copy headers.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains a legitimate S3 presigned PUT URL for a target bucket managed by NooBaa.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request using the presigned URL.\u003c/li\u003e\n\u003cli\u003eAttacker injects an unauthorized 'x-amz-copy-source' header into the request.\u003c/li\u003e\n\u003cli\u003eThe noobaa-core component processes the request and calculates the SigV4 signature.\u003c/li\u003e\n\u003cli\u003eThe vulnerability in the verification logic ignores the unsigned 'x-amz-copy-source' header during signature validation.\u003c/li\u003e\n\u003cli\u003eThe gateway grants the request based on the valid signature of the original PUT request.\u003c/li\u003e\n\u003cli\u003eThe system executes the CopyObject operation, allowing the attacker to access and copy unauthorized data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized access to data within the NooBaa storage environment. By performing unintended CopyObject operations, an attacker can exfiltrate sensitive files or directories to which they would otherwise lack permission, bypassing established authorization controls. This vulnerability impacts all deployments relying on NooBaa Multicloud Object Gateway for S3-compatible storage services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the noobaa-core component to the version that addresses CVE-2026-94368.\u003c/li\u003e\n\u003cli\u003eAudit web server and storage gateway access logs for suspicious occurrences of the 'x-amz-copy-source' header in requests that originate from unauthorized or unexpected users.\u003c/li\u003e\n\u003cli\u003eImplement strict request validation for S3 SigV4 requests to ensure all headers used for authorization logic are properly verified and non-compliant requests are dropped.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T12:28:24Z","date_published":"2026-09-21T12:28:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-noobaa-sigv4-bypass/","summary":"A signature verification flaw in the noobaa-core component allows attackers to manipulate S3 presigned URLs, leading to unauthorized object copy operations and data access.","title":"Authorization Bypass in NooBaa Multicloud Object Gateway via SigV4","url":"https://feed.craftedsignal.io/briefs/2026-09-noobaa-sigv4-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Noobaa-Core","version":"https://jsonfeed.org/version/1.1"}