Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77317— SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite

Quick assessment

Affected
seaweedfs seaweedfs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SeaweedFS 是一个用于文件和 Blob 的分布式存储系统。在 3.88 至 4.39 版本中,SFTP 服务在评估配置的路径权限时采用“字面字符串前缀”匹配方式,导致被限制在特定路径下的用户,也能访问任何仅以相同字符开头的同级路径。因此,一个被授予 /tenants/alice 访问权限的用户,同样会匹配到 /tenants/alice-archive、/tenants/alice2 等类似路径,因为该检查未强制要求路径组件边界。一个拥有根目录为家目录且具有狭窄路径权限的已认证低权限 SFTP 用户,从而可

CVSS 8.1 · High

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77317

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read and overwrite
Source: CVE Program / CVE List V5
Vulnerability Description
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user granted access to /tenants/alice therefore also matches /tenants/alice-archive, /tenants/alice2, and similar siblings, because the check does not require a path-component boundary. An authenticated low-privilege SFTP user with a root home directory and narrow path permissions can thereby cross the configured ACL boundary to read another tenant's files, and to overwrite them if granted write, all through the documented SFTP service with its own valid credentials. This issue is fixed in version 4.40.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
seaweedfs seaweedfs >= 3.88, < 4.40 -

II. Public POCs for CVE-2026-77317

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77317

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77317 (1)

Vendor Advisories for CVE-2026-77317 (1)

Same Patch Batch · seaweedfs · 2026-08-26 · 4 CVEs total

CVE-2026-77298 8.7 HIGH SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy
CVE-2026-77368 7.6 HIGH SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbitrary Write to
CVE-2026-77611 7.1 HIGH SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwriting a diffe

IV. Related Vulnerabilities

V. Comments for CVE-2026-77317

No comments yet


Leave a comment