Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, creating a critical authentication bypass vulnerability. Unauthenticated attackers can extract usernames from unsigned Authorization headers and impersonate any user, including privileged service accounts. This allows attackers to perform unauthorized read, write, and delete operations on arbitrary data. The vulnerability affects Alluxio through version 2.9.5. The flaw stems from the proxy not enforcing signature verification, meaning any attacker with network access can spoof user identities without valid credentials. This poses a significant risk to data integrity and confidentiality in environments using Alluxio's S3-compatible interface.