← Volver al buscador de CVEs

CVE-2026-77317

SeaweedFS

Descripción

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alice-archive, /tenants/alice2, and similar siblings, because the check does not require a path-component boundary. An authenticated low-privilege SFTP user with a root home directory and narrow path permissions can thereby cross the configured ACL boundary to read another tenant-s files, and to overwrite them if granted write, all through the documented SFTP service with its own valid credentials. This issue is fixed in version 4.40.

CVSS 8.1EPSS 0.22%Riesgo 0.83
Ver fuente
Publicación
2026-08-26 22:16:29
Versiones afectadas
>=3.88,<=4.39
Tipo
Librería
Última modificación
2026-08-26 22:16:29
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N