PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58372 seaweedfs CVE debrief

SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in the DeleteObjects XML request body. This vulnerability enables attackers to bypass authorization controls through a confused deputy condition, as the validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys. Consequently, the filer path can collapse directory traversal sequences and resolve deletions outside the authorized bucket, potentially

Vendor
seaweedfs
Product
Unknown
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-10-08
Advisory published
2026-06-30
Advisory updated
2026-10-08

Who should care

Defenders responsible for SeaweedFS deployments, S3 bucket administrators, and security teams should assess exposure and prioritize remediation. They should verify the SeaweedFS version, restrict write access to S3 buckets, and monitor S3 bucket activity for unauthorized object deletions. Additionally, they should review compensating controls for exposed systems and track exceptions and retest remediated assets.

Why it matters

CVE-2026-58372 is a high-severity vulnerability in SeaweedFS that allows authenticated users to delete objects across buckets, potentially leading to data loss or corruption. Defenders should prioritize verification and remediation.

  • Potential unauthorized deletion of objects across S3 buckets
  • Bypass of authorization controls through confused deputy condition
  • Possible data loss or corruption due to arbitrary object deletion
  • Need for verification of SeaweedFS version and exposure

Technical summary

The vulnerability is caused by a path traversal issue in the DeleteMultipleObjectsHandler of the S3 gateway in SeaweedFS. This allows an authenticated S3 principal with write access to a single bucket to delete objects in other buckets by providing object keys with ../ sequences in the DeleteObjects XML request body. The validateRequestPath middleware only inspects URL-captured path variables and never examines request-body keys, enabling the filer path to collapse directory traversal sequences and resolve deletions outside the authorized bucket.

Defensive priority

Defenders should prioritize verifying and upgrading to SeaweedFS version 4.34 or later to prevent unauthorized object deletion across buckets.

Recommended defensive actions

  • Verify SeaweedFS version and upgrade to 4.34 or later if necessary
  • Restrict write access to S3 buckets to only required users and roles
  • Monitor S3 bucket activity for unauthorized object deletions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is confirmed in SeaweedFS versions before 4.34. The CVE Program and NVD provide official records of the vulnerability. Evidence is based on the official CVE record and NVD vulnerability detail. Defenders should verify the SeaweedFS version and assess exposure. The CVE Program and NVD provide official records of the vulnerability, but additional details may be limited. Further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58372 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58372

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58372 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58372

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58372.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/seaweedfs/seaweedfs/releases/tag/4.34

    Supplemental source - release-notes

  • Source reference

    Unverified legacy reference

    URL: https://github.com/seaweedfs/seaweedfs/pull/9931

    Supplemental source - related, issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/seaweedfs/seaweedfs/commit/0345658ea8e7c6a3948ad190634b00866ec244c9

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-w62w-66v9-vvgv

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/geo-chen/oss/blob/main/seaweedfs.md

    Supplemental source - technical-description, exploit

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/seaweedfs-cross-bucket-object-deletion-via-deleteobjects-request-body-keys

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.