← Back to overview

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, creating a critical authentication bypass vulnerability. Unauthenticated attackers can extract usernames from unsigned Authorization headers and impersonate any user, including privileged service accounts. This allows attackers to perform unauthorized read, write, and delete operations on arbitrary data. The vulnerability affects Alluxio through version 2.9.5. The flaw stems from the proxy not enforcing signature verification, meaning any attacker with network access can spoof user identities without valid credentials. This poses a significant risk to data integrity and confidentiality in environments using Alluxio's S3-compatible interface.

Affected products

  • Alluxio S3 REST Proxy
  • Alluxio through 2.9.5

Related CVE's

  • CVE-2026-79787

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Database & Storage
  • Identity & Access