{"apiVersion":"1.0","identifier":"CVE-2026-77317","description":"SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alice-archive, /tenants/alice2, and similar siblings, because the check does not require a path-component boundary. An authenticated low-privilege SFTP user with a root home directory and narrow path permissions can thereby cross the configured ACL boundary to read another tenant-s files, and to overwrite them if granted write, all through the documented SFTP service with its own valid credentials. This issue is fixed in version 4.40.","publishedAt":"2026-08-26T22:16:29","lastModifiedAt":"2026-08-26T22:16:29","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77317","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","epssProbability":0.0022,"riskScore":0.83,"affectedProduct":"SeaweedFS","affectedVersions":">=3.88,<=4.39","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-77317","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-77317","en":"https://www.redsauce.net/en/cves/CVE-2026-77317","fr":"https://www.redsauce.net/fr/cves/CVE-2026-77317","pt":"https://www.redsauce.net/pt/cves/CVE-2026-77317","de":"https://www.redsauce.net/de/cves/CVE-2026-77317","sk":"https://www.redsauce.net/sk/cves/CVE-2026-77317","el":"https://www.redsauce.net/el/cves/CVE-2026-77317"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-77317"}}