CVE-2026-72920
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without manda
CVSS
9.8
Critical
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-306
Not enough EPSS history yet.
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
- github.comhttps://github.com/seaweedfs/seaweedfs/commit/5e8f99f40a8abc7b449aefd260516443377041c7
- github.comhttps://github.com/seaweedfs/seaweedfs/pull/9442
- github.comhttps://github.com/seaweedfs/seaweedfs/releases/tag/4.24
- github.comhttps://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-2v6v-25fm-p4fg
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-649218.8 HIG—
———Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.6hCVE-2026-627777.8 HIG—
———Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.6hCVE-2026-613677.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613657.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613647.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6hCVE-2026-613567.8 HIG—
———Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.6h