SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 15:17
Updated : 2026-09-09 20:46
NVD link : CVE-2026-72920
Mitre link : CVE-2026-72920
CVE.ORG link : CVE-2026-72920
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
