THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hgpf-8634-g44c (medium) — SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

[GHSA] GHSA-hgpf-8634-g44c (medium) — SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

medgithub_advisoriesPublished 2026-08-28

GHSA-hgpf-8634-g44c Severity: medium CVE: CVE-2026-55873

SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets

### Summary SeaweedFS routes requests signed with SigV4 service `s3tables` to the S3Tables management API. Authorization on that path collapsed account-less S3 identities into the shared

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hgpf-8634-g44c