PatchSiren cyber security CVE debrief
CVE-2026-58372 seaweedfs CVE debrief
SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in the DeleteObjects XML request body. This vulnerability enables attackers to bypass authorization controls through a confused deputy condition, as the validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys. Consequently, the filer path can collapse directory traversal sequences and resolve deletions outside the authorized bucket, potentially
- Vendor
- seaweedfs
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for SeaweedFS deployments, S3 bucket administrators, and security teams should assess exposure and prioritize remediation. They should verify the SeaweedFS version, restrict write access to S3 buckets, and monitor S3 bucket activity for unauthorized object deletions. Additionally, they should review compensating controls for exposed systems and track exceptions and retest remediated assets.
Why it matters
CVE-2026-58372 is a high-severity vulnerability in SeaweedFS that allows authenticated users to delete objects across buckets, potentially leading to data loss or corruption. Defenders should prioritize verification and remediation.
- Potential unauthorized deletion of objects across S3 buckets
- Bypass of authorization controls through confused deputy condition
- Possible data loss or corruption due to arbitrary object deletion
- Need for verification of SeaweedFS version and exposure
Technical summary
The vulnerability is caused by a path traversal issue in the DeleteMultipleObjectsHandler of the S3 gateway in SeaweedFS. This allows an authenticated S3 principal with write access to a single bucket to delete objects in other buckets by providing object keys with ../ sequences in the DeleteObjects XML request body. The validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys, enabling the filer path to collapse directory traversal sequences and resolve deletions outside the authorized bucket.
Defensive priority
Defenders should prioritize verifying and upgrading to SeaweedFS version 4.34 or later to prevent unauthorized object deletion across buckets.
Recommended defensive actions
- Verify SeaweedFS version and upgrade to 4.34 or later if necessary
- Restrict write access to S3 buckets to only required users and roles
- Monitor S3 bucket activity for unauthorized object deletions
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is confirmed in SeaweedFS versions before 4.34. The CVE Program and NVD provide official records of the vulnerability. Evidence is based on the official CVE record and NVD vulnerability detail. Defenders should verify the SeaweedFS version and assess exposure. The CVE Program and NVD provide official records of the vulnerability, but additional details may be limited. Further verification is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58372 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58372
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58372 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58372
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58372.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/seaweedfs/seaweedfs/releases/tag/4.34
Supplemental source - release-notes
-
Source reference
Unverified legacy reference
URL: https://github.com/seaweedfs/seaweedfs/pull/9931
Supplemental source - related, issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/seaweedfs/seaweedfs/commit/0345658ea8e7c6a3948ad190634b00866ec244c9
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/geo-chen/oss/blob/main/seaweedfs.md
Supplemental source - technical-description, exploit
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/seaweedfs-cross-bucket-object-deletion-via-deleteobjects-request-body-keys
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.