THREAT OPS › Threat News › [GHSA] GHSA-hgpf-8634-g44c (medium) — SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
[GHSA] GHSA-hgpf-8634-g44c (medium) — SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
GHSA-hgpf-8634-g44c Severity: medium CVE: CVE-2026-55873
SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets
### Summary SeaweedFS routes requests signed with SigV4 service `s3tables` to the S3Tables management API. Authorization on that path collapsed account-less S3 identities into the shared
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55873cve
Original source: https://github.com/advisories/GHSA-hgpf-8634-g44c