Description
SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SeaweedFS distributed storage systems exposed a weakness in the S3Tables/Iceberg REST management API that allowed requests signed with Sig service to be routed to an internal API without proper credential checks. The authorization logic collapsed identities into a shared administrator account and failed open, meaning any S3 user with basic credentials could enumerate the names and ARNs of table buckets owned provide sensitive internal resource information that could aid further attacks.

Affected Systems

SeaweedFS version 4.08 through 4.33 are affected. The fix was delivered in release 4.34; systems running any later version have this issue corrected.

Risk and Exploitability

.3 indicates moderate severity, and the EPSS score of <1% reflects a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated low‑privileged S3 user who can sign SigV4 requests for the s3tables service; this path requires only legitimate access credentials and does not lead to code execution or availability compromise, but it does reveal internal identifiers.

Generated by OpenCVE AI on July 23, 2026 at 11:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SeaweedFS to version 4.34 or later to apply the fix.
  • Restrict the S3 credentials granted to the s3tables service so that only privileged users can access the management API.
  • Set up monitoring or logging to detect enumeration activity against table bucket namespaces.

Generated by OpenCVE AI on July 23, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Seaweedfs
Seaweedfs seaweedfs
Vendors & Products Seaweedfs
Seaweedfs seaweedfs

Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables are routed to the S3Tables management API where authorization collapses account-less S3 identities into the shared admin account and fails open, allowing an authenticated low-privileged S3 user to enumerate administrator-owned table bucket names and ARNs. This issue is fixed in version 4.34.
Title SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Seaweedfs Seaweedfs
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T15:33:34.018Z

Reserved: 2026-06-17T16:59:42.758Z

Link: CVE-2026-55873

cve-icon Vulnrichment

Updated: 2026-07-08T15:33:31.160Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T12:00:05Z

Weaknesses