CVE-2026-55873: SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

Published Jul 8, 2026
·
Updated

SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.

Affected Software

2 affected components
seaweedfs seaweedfs>=4.08<=4.33
seaweedfs seaweedfs=4.34

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade SeaweedFS to a version that resolves this vulnerability.

    Fixed in 4.34

Event History

Jul 8, 2026
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-55873?

CVE-2026-55873 has a medium severity rating of 4.3.

2

What vulnerability does CVE-2026-55873 address?

CVE-2026-55873 addresses improper authorization in the SeaweedFS S3Tables and Iceberg REST management API.

3

How does CVE-2026-55873 impact SeaweedFS users?

CVE-2026-55873 impacts SeaweedFS users by allowing low-privileged S3 users to enumerate administrator-owned table buckets.

4

What versions of SeaweedFS are affected by CVE-2026-55873?

SeaweedFS versions 4.08 through 4.33 are affected by CVE-2026-55873.

5

How can I mitigate the risks of CVE-2026-55873?

To mitigate the risks of CVE-2026-55873, users should upgrade to a version of SeaweedFS that addresses the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203