CVE-2026-79787
Last modified
CVE-2026-79787 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data..
Description
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Alluxio | alluxio | <= 2.9.5 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-79787?
How severe is CVE-2026-79787?
How do I fix CVE-2026-79787?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-79781rclone serve s3 before 1.74.4 contains a path traversal vuln…6.5
- CVE-2026-79782rclone before 1.74.4 fails to strip the X-Amz-Security-Token…3.1
- CVE-2026-79783rclone before 1.74.4 fails to mask special permission bits w…3.6
- CVE-2026-79784Vocos instantiates a class named by a configuration file wit…8.8
- CVE-2026-79785X-AnyLabeling's model downloader disabled TLS certificate ve…5.9
- CVE-2026-79786Coroot's unauthenticated MCP OAuth dynamic client registrati…7.1
- CVE-2026-79788In Dradis Community Edition, the ProvidersController and Age…7.1
- CVE-2026-7979Inappropriate implementation in Media in Google Chrome prior…4.3
- CVE-2026-79792A flaw has been found in zackees transcribe-anything up to 4…5.6
- CVE-2026-79793A vulnerability has been found in code-projects Online Shopp…4.3
- CVE-2026-7980Use after free in WebAudio in Google Chrome prior to 148.0.7…8.8
- CVE-2026-79804A vulnerability was found in SililaWijesinghe Food Ordering …7.3
Are you affected by CVE-2026-79787?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
