Junglewise Threat Intelligence

CVE-2026-77368: SeaweedFS TUS resumable-upload JWT authorization bypass

CVE-2026-77368 · Severity: high · CVSS 7.6 · Published 2026-08-26

Technologies: SeaweedFS. Vendors: SeaweedFS.

Executive brief

SeaweedFS is a distributed storage system used to store and manage files and blobs across multiple nodes. In version 4.39, a multi-tenant deployment using JWT token scoping can be exploited by a low-privilege tenant to hijack other tenants' file uploads, write content to forbidden storage paths, read upload progress, and delete other users' sessions—compromising data isolation and potentially leading to unauthorized file placement or data loss.

Technical details

The vulnerability is an authorization bypass in the TUS (Tus Resumable Upload Protocol) handler. The filer's JWT scope check (allowed_prefixes) is only enforced when a new upload session is created (POST), but the HEAD, PATCH, and DELETE operations that manipulate existing sessions by session ID do not verify that the session's stored target path falls within the caller's allowed prefixes. A low-privilege tenant who learns another tenant's session ID (which, while unguessable to unauthenticated users, is not an authorization boundary against legitimate tenants) can modify that session to write attacker-controlled bytes to arbitrary paths, delete other sessions, or read progress metadata. This affects only deployments with JWT signing configured and TUS uploads enabled. The vulnerability was fixed in version 4.40 by validating the session target path on all operations and failing closed when resolution fails.

Affected products

  • SeaweedFS SeaweedFS 4.39

Timeline

  • 2026-08-26: disclosed
  • 2026-07-10: patched: Fix commits merged; version 4.40 released

References

Related threats