CVE-2026-26187Disclosure(lakefs / lakefs)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lakefs lakefs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to read and write files outside their designated storage boundaries. The verifyRelPath function used strings.HasPrefix() to verify that requested paths fall within the configured storage directory. This check was insufficient because it validated only the path prefix without requiring a path separator, allowing access to sibling directories with similar names. Also, the adapter verified that resolved paths stayed within the adapter's base path, but did not verify that object identifiers stayed within their designated storage namespace. This allowed attackers to use path traversal sequences in the object identifier to access files in other namespaces. Fixed in version v1.77.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lakefs

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-13); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
lakefs

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-13: 4Mentions · 2026-02-14: 1Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-14: 1Technical Details · 2026-02-13: 4Technical Details · 2026-02-14: 1Technical Details · 2026-02-18: 102-1302-1402-18
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-134
Disclosure4
2026-02-141
Patch1
2026-02-181
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26187 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allow… https://www.cve.org/CVERecord?id=CVE-2026-26187

    Post summary

    The text announces CVE-2026-26187 as a vulnerability affecting lakeFS's local block adapter before version 1.77.0, providing some technical context but no PoC, exploit, or patch information.

    00020198
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26187 Path Traversal Vulnerability in lakeFS Local Block Adapter Before v1.77.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26187

    Post summary

    The text announces a path traversal vulnerability in lakeFS Local Block Adapter before v1.77.0, providing limited technical details but no information on PoC, exploits, or patches.

    0001027
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26187 (CVSS:8.1, HIGH) is Awaiting Analysis. lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local bl..https://nvd.nist.gov/vuln/detail/CVE-2026-26187 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-26187 is a high‑severity vulnerability (CVSS 8.1) affecting lakeFS versions before 1.77.0, currently awaiting analysis with no available exploit or patch information.

    0000040
    171 followersView on X
  • CyberLen AI@views2day
    Patch

    🚨 Security Digest: Feb 13, 2026 2 critical vulnerabilities dropped: • lakeFS - path traversal flaw (CVE-2026-26187) • WildFly - brute force risk (CVE-2025-23368) If you're running either, patch now. Full details: http://cyberlensai.com/news/security-digest-2026-02-13

    Post summary

    The digest announces two critical CVEs—path traversal in lakeFS and brute force risk in WildFly—and urges users to apply patches promptly.

    0000048
    915 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26187 - High lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local block adapter (pkg/block/local/adapter.go) allows authenticated users to ... https://www.thehackerwire.com/vulnerability/CVE-2026-26187/ https://t.co/LvC6UDa77X

    Post summary

    The text announces a high‑severity vulnerability (CVE‑2026‑26187) in lakeFS’s local block adapter, noting that authenticated users can exploit it; no PoC, exploit code, or patch details are provided.

    0000035
    112 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26187: CVE-2026-26187: escaping the Lake with a Path Traversal Two-Step A critical path traversal vulnerability in the lakeFS Local Block Adapter allows authenticated users to break out of their storage namespace boundaries. By exploiting a w... https://cvereports.com/reports/CVE-2026-26187

    Post summary

    This is a disclosure of a new CVE (CVE‑2026‑26187), highlighting a critical path traversal flaw in lakeFS’s Local Block Adapter that lets authenticated users escape their storage namespace boundaries.

    0000028
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applakefslakefs---

Explore more