THREAT OPS › Threat News › [NVD] CVE-2026-77317 (HIGH 8.1) — SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose n
[NVD] CVE-2026-77317 (HIGH 8.1) — SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose n
CVE-2026-77317 CVSS: 8.1 HIGH Published: 2026-08-26T22:16:29.717
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a literal string-prefix comparison, so a user scoped to a path is also granted the same access to any sibling path whose name merely begins with the same characters. A user gra
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-77317cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77317