THREAT OPS › Threat News › [GHSA] GHSA-2v6v-25fm-p4fg (critical) — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
[GHSA] GHSA-2v6v-25fm-p4fg (critical) — SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
GHSA-2v6v-25fm-p4fg Severity: critical CVE: CVE-2026-72920
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
### Impact The filer registered the IAM gRPC service (`SeaweedIdentityAccessManagement`) with no authentication. Any client able to reach the filer gRPC port could invoke IAM RPCs — `CreateUser`, `CreateAccessKey`, `PutUserPolicy`, and related calls — to m
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-72920cve
Original source: https://github.com/advisories/GHSA-2v6v-25fm-p4fg