CVE-2026-72920Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-11: 2Mentions · 2026-09-03: 1PoC Mentioned / Linked · 2026-08-11: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-08-11: 1Technical Details · 2026-09-03: 108-1109-03
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-112
Disclosure1PoC1
2026-09-031
Disclosure1
Full discourse3 posts
  • Aretiq.AI@AretiqAI
    PoC

    ARETIQ Daily Vulnerability Bulletin — August 11, 2026 🔴 CRITICAL: CVE-2026-48362 (adobe/coldfusion_2025) AAS 13.8 🔴 CRITICAL: CVE-2026-71362 (adobe/adobe_commerce) AAS 13.8 — PoC available 🔴 CRITICAL: CVE-2026-72785 (craftcms/cms) AAS 13.5 — PoC available 🔴 CRITICAL: CVE-2026-72920 (seaweedfs/seaweedfs) AAS 13.1 — PoC available 🔴 CRITICAL: CVE-2026-46670 (yeswiki/yeswiki) AAS 12.4 — PoC available + 4 more CRITICAL 111 vulnerabilities — CRITICAL: 9, HIGH: 102 Full bulletin: https://aretiq.ai/bulletins/2026-08-11/

    Post summary

    The bulletin announces multiple critical CVEs and confirms Proof of Concept (PoC) availability for several of them, but it does not provide exploit code, active exploitation reports, patches, or technical vulnerability details.

    010951.0K
    232 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 SeaweedFS Filer, Missing Authentication for Critical Function, #CVE-2026-72920 (Critical) -DC-Sep2026-2109 https://dailycve.com/seaweedfs-filer-missing-authentication-for-critical-function-cve-2026-72920-critical-dc-sep2026-2109/

    Post summary

    The post announces the discovery of a critical SeaweedFS Filer vulnerability (CVE‑2026‑72920) characterized by missing authentication for a critical function, but does not provide PoC, exploit code, or remediation details.

    0000049
    233 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - SeaweedFS Unauthenticated IAM gRPC Access Leads to S3 Admin Takeover (CVE-2026-72920) In SeaweedFS before 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset. Any client that can reach the filer gRPC port can call IAM RPCs like CreateUser, CreateAccessKey, and PutPolicy to mint their own credentials and gain full S3 administrative control. That means an unauthenticated attacker can hand themselves admin access keys and then read, modify, or delete all stored data. CISA rates it automatable, and the impact is total. CVSS 9.8. 👉Upgrade SeaweedFS to 4.24, set jwt.filer_signing.key, and restrict network access to the filer gRPC port.

    Post summary

    The post announces a severe CVE‑2026‑72920 in SeaweedFS that allows unauthenticated gRPC access to full S3 admin control, and recommends upgrading to version 4.24 and setting a signing key.

    0000082
    285 followersView on X

Explore more