What is CVE-2026-72920?
CVE-2026-72920 is a vulnerability in SeaweedFS versions before 4.24 where the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset. This allows any client with network access to the filer gRPC port to invoke sensitive commands like CreateUser, CreateAccessKey, and PutPolicy. Affected deployments must configure jwt.filer_signing.key or upgrade to version 4.24.
Azərbaycanca: CVE-2026-72920 SeaweedFS-in 4.24-dən əvvəl versiyalarında filer-in jwt.filer_signing.key təyin edilmədikdə SeaweedIdentityAccessManagement gRPC xidmətini autentifikasiyasız qeydiyyatdan keçirməsi zəifliyidir. Bu, filer gRPC portuna çatan istənilən müştəriyə CreateUser, CreateAccessKey, PutPolicy kimi əmrləri icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə mütləq jwt.filer_signing.key konfiqurasiya edilməli və ya 4.24 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What commands can an attacker exploiting CVE-2026-72920 execute in SeaweedFS?
CreateUser, CreateAccessKey, PutPolicy.
What measure should be taken to prevent CVE-2026-72920 in SeaweedFS?
Set jwt.filer_signing.key or upgrade to version 4.24.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.