PULSE
LIVE16signals / 24h
FEED
ransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcareransomorova reclama a Ganzhou Xinye Craft Co., Ltd. · HK · Manufacturingransompanzer reclama a Xpress Tech · Technologyransomqilin reclama a G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L · IT · Transportationransomqilin reclama a Crown Group · PK · Otherransomdragonforce reclama a QPC Global · GB · Otherransominterlock reclama a AngMar Companies · Not Foundransompayload reclama a B&B Hydraulik · DE · Manufacturingransompayload reclama a Stücheli Architekten · CH · Professional Servicesransompayload reclama a Baya Technologies · Technologyransomkrybit reclama a www.kilpi-koskinen.fi · FI · Otherransomkrybit reclama a www.apsanet.com.ar · AR · Professional Servicesransomqilin reclama a Service Evaluation Concepts · US · Professional Servicesransomqilin reclama a tommer construction · US · Manufacturingransomdirewolf reclama a Leafwell · US · Healthcare
← All CVEs
CVE WatchAug 11, 2026

CVE-2026-72920

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without manda

CVSS

9.8

Critical

EPSS

KEV

Exploit Today

0-100

Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-306

EPSS · 30d

Not enough EPSS history yet.

Technical description

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-649218.8 HIG
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.6h
CVE-2026-627777.8 HIG
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613677.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613657.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613647.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h
CVE-2026-613567.8 HIG
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h