CVE-2026-79787Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Disclousure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-25); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-25: 2Mentions · 2026-08-28: 1Mentions · 2026-09-18: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-08-25: 2Technical Details · 2026-08-28: 1Technical Details · 2026-09-18: 108-2508-2809-18
Signal classification3 categories
Disclosure
250.0%
Disclousure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-252
Disclosure2
2026-08-281
Disclousure1
2026-09-181
Patch1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-79787 Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. At… https://www.cve.org/CVERecord?id=CVE-2026-79787

    Post summary

    Alluxio's S3 REST proxy vulnerability (CVE‑2026‑79787) allows unauthenticated attackers to spoof user identity because the proxy does not verify AWS Signature V4 signatures, as outlined in the CVE record.

    000101.6K
    58.0K followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    CVE-2026-79787。Alluxio の S3 REST プロキシが既定で AWS 署名を検証せず、Authorization ヘッダに書いた名前でなりすませます。CVSS 9.8 で修正版は未公表。署名検証の設定は既定が false なので、true にして塞ぎます https://cve.autoarticles.net/cve/CVE-2026-79787

    Post summary

    CVE‑2026–79787 reveals a critical Alluxio S3 REST proxy flaw allowing impersonation due to missing AWS signature verification (CVSS 9.8). No patch is available yet, but enabling signature verification (setting it to true) is advised as a workaround.

    0000059
    556 followersView on X
  • Vistem Solutions@VistemSolutions
    Disclousure

    CVE-2026-79787: alluxio Authentication Bypass (CVSS 9.8) CVE-2026-79787 is a critical-severity vulnerability in Alluxio. Its S3 REST proxy fails to verify AWS Signature Version 4 signatures in its request flow, potentially allowing unauthorized access. If your organization uses Alluxio, review exposure immediately, restrict access to trusted networks, monitor logs for suspicious S3 proxy activity, and apply vendor-recommended patches or mitigations as soon as available. Secure innovation starts with proactive action. #Cybersecurity #CVE #Alluxio #VulnerabilityManagement #CyberResilience #VistemSolutions #VistemSecurePro https://www.strix.ai/cve/CVE-2026-79787?utm_source=in_page&utm_medium=Vistem+Solutions%2C+Inc.&utm_campaign=publer

    Post summary

    The post announces a critical Alluxio authentication bypass (CVE‑2026‑79787), describes its technical details, and advises users to apply available vendor patches promptly.

    0000053
    87 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-79787 Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. At… https://www.cve.org/CVERecord?id=CVE-2026-79787 ----- Traducción: CVE-2026-79787 El … https://infoflow.cloud`

    Post summary

    The post announces that Alluxio’s S3 REST proxy does not validate AWS SigV4 signatures, enabling unauthenticated attackers to spoof user identity per CVE‑2026‑79787.

    0000038
    102 followersView on X

Explore more