{"id":"CVE-2026-72921","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-72921","summary":"SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so…","details":"SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.","published":"2026-08-11T15:17:38.217","modified":"2026-08-11T15:17:38.217","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/seaweedfs/seaweedfs/commit/05ed5c9ae8a2a45101b52b61d02f170d20d587ff","label":"seaweedfs/seaweedfs@05ed5c9"},"references":[{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/commit/05ed5c9ae8a2a45101b52b61d02f170d20d587ff"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/pull/9439"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/releases/tag/4.24"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-gv5w-hfx8-8cwq"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-11T15:17:38.217"}}