CVE-2026-77298
Last modified
CVE-2026-77298 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM role without enforcing that role's trust policy, so a federated user can assume a role they are not permitted to hold. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly in the Authorization header and maps it to an IAM role without enforcing that role's trust policy, so a federated user can assume a role they are not permitted to hold. The standard STS AssumeRoleWithWebIdentity path rejects such a token when the role's trust policy does not trust the token's federated provider, but the direct S3 bearer path validates only the token itself and then authenticates as the mapped role and evaluates that role's attached S3 permissions. As a result, a valid OIDC user whose token would be denied the role through STS can obtain the role's S3 access, including object read, write, and delete, by presenting the raw OIDC JWT directly to the S3 API. This issue is fixed in version 4.40
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| seaweedfs | seaweedfs | < 4.40 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-77298?
How severe is CVE-2026-77298?
How do I fix CVE-2026-77298?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7725A vulnerability was found in PrefectHQ prefect up to 3.6.25.…6.3
- CVE-2026-7726The Layouts for WPBakery plugin for WordPress is vulnerable …6.5
- CVE-2026-77264The Automation Web Platform – Notifications and OTP for WooC…9.8
- CVE-2026-7727A vulnerability was determined in Shandong Hoteam Software P…7.3
- CVE-2026-7728A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0…6.3
- CVE-2026-7729A security flaw has been discovered in pixelsock directus-mc…6.3
- CVE-2026-7730A weakness has been identified in privsim mcp-test-runner 0.…6.3
- CVE-2026-7731A security vulnerability has been detected in code-projects …6.3
- CVE-2026-77310jackson-databind contains the general-purpose data-binding f…5.3
- CVE-2026-77317SeaweedFS is a distributed storage system for files and blob…8.1
- CVE-2026-7732A vulnerability was detected in code-projects BloodBank Mana…6.3
- CVE-2026-7733A flaw has been found in funadmin up to 7.1.0-rc6. This affe…7.3
Are you affected by CVE-2026-77298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
