← Back to overview

CVE-2026-77611 affects SeaweedFS, a distributed storage system, in versions prior to 4.40. An authenticated S3 principal with permissions scoped to a nested object key can exploit a flaw in the PutObjectAcl handler to overwrite objects outside their permitted scope. The vulnerability exists because the handler authorizes requests against the nested key but writes the updated entry back to the bucket root instead of the key's actual parent directory. This results in an existing target object being overwritten with the content, metadata, owner information, and ACL of the scoped object. The flaw effectively bypasses object-level action scoping configured through the static S3 identity file. The issue has been patched in SeaweedFS version 4.40.

Affected products

  • SeaweedFS

Related CVE's

  • CVE-2026-77611

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Identity & Access