CVE-2026-55873: SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SeaweedFSto a version that resolves this vulnerability.Fixed in 4.34
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55873?
CVE-2026-55873 has a medium severity rating of 4.3.
What vulnerability does CVE-2026-55873 address?
CVE-2026-55873 addresses improper authorization in the SeaweedFS S3Tables and Iceberg REST management API.
How does CVE-2026-55873 impact SeaweedFS users?
CVE-2026-55873 impacts SeaweedFS users by allowing low-privileged S3 users to enumerate administrator-owned table buckets.
What versions of SeaweedFS are affected by CVE-2026-55873?
SeaweedFS versions 4.08 through 4.33 are affected by CVE-2026-55873.
How can I mitigate the risks of CVE-2026-55873?
To mitigate the risks of CVE-2026-55873, users should upgrade to a version of SeaweedFS that addresses the vulnerability.