{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/alluxio/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-79787"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["alluxio"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-79787","alluxio"],"_cs_type":"advisory","_cs_vendors":["Alluxio"],"content_html":"\u003cp\u003eAlluxio's S3 REST proxy, used in versions 2.9.5 and earlier, is vulnerable to an authentication bypass due to a failure to verify AWS Signature Version 4 (SigV4) signatures in its default configuration. This flaw allows unauthenticated remote attackers to impersonate any user or service account by manipulating the Authorization header. Because the proxy does not validate the integrity or authenticity of the provided credentials, attackers can supply arbitrary usernames to gain unauthorized access to the underlying storage resources. This allows for full read, write, and delete operations on data managed by Alluxio. Given that this component is often used in data platform architectures, the impact of unauthorized data manipulation or exfiltration is severe. Organizations should prioritize updating Alluxio instances to the recommended patched versions once available to prevent unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance on the Alluxio deployment to identify the S3 REST proxy endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request to the target S3 proxy endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a malformed or arbitrary \u0026quot;Authorization\u0026quot; header containing a target username into the request.\u003c/li\u003e\n\u003cli\u003eThe Alluxio S3 REST proxy receives the request and parses the Authorization header.\u003c/li\u003e\n\u003cli\u003eThe proxy fails to cryptographically verify the signature associated with the provided identity.\u003c/li\u003e\n\u003cli\u003eThe proxy incorrectly authenticates the request based solely on the user-provided identity in the header.\u003c/li\u003e\n\u003cli\u003eThe proxy executes the requested data operation (read, write, or delete) with the permissions of the impersonated user.\u003c/li\u003e\n\u003cli\u003eThe final objective is reached: unauthorized access, modification, or exfiltration of sensitive data stored within the Alluxio system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain full administrative control over data managed by the S3 REST proxy. This includes reading sensitive datasets, overwriting or corrupting existing data, and deleting critical information. The vulnerability affects all Alluxio deployments using the default S3 REST proxy configuration up to and including version 2.9.5.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all Alluxio deployments to confirm version usage; upgrade to a patched version immediately upon release (CVE-2026-79787).\u003c/li\u003e\n\u003cli\u003eImplement strict network access control lists (ACLs) to restrict access to the Alluxio S3 REST proxy endpoint to trusted internal networks only.\u003c/li\u003e\n\u003cli\u003eEnable verbose access logging for the S3 REST proxy and alert on any requests containing suspicious or non-standard Authorization headers, as the application logic currently fails to validate them.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to monitor for unauthorized requests targeting the S3 proxy endpoint (see rule below).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T20:49:15Z","date_published":"2026-08-25T20:49:15Z","id":"https://feed.craftedsignal.io/briefs/2026-08-alluxio-s3-auth-bypass/","summary":"Alluxio versions 2.9.5 and earlier contain a critical authentication vulnerability that allows unauthenticated attackers to spoof identity and perform unauthorized operations by failing to verify AWS Signature Version 4 requests.","title":"Authentication Bypass in Alluxio S3 REST Proxy","url":"https://feed.craftedsignal.io/briefs/2026-08-alluxio-s3-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Alluxio","version":"https://jsonfeed.org/version/1.1"}