THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2v6v-25fm-p4fg (critical) — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

[GHSA] GHSA-2v6v-25fm-p4fg (critical) — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

medgithub_advisoriesPublished 2026-09-02

GHSA-2v6v-25fm-p4fg Severity: critical CVE: CVE-2026-72920

SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control

### Impact The filer registered the IAM gRPC service (`SeaweedIdentityAccessManagement`) with no authentication. Any client able to reach the filer gRPC port could invoke IAM RPCs — `CreateUser`, `CreateAccessKey`, `PutUserPolicy`, and related calls — to m

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2v6v-25fm-p4fg