Summary
CVE-2026-72920 is a Missing Authentication for Critical Function vulnerability (CWE-306) in SeaweedFS. The filer’s IAM gRPC service registers and accepts requests without any authentication when the jwt.filer_signing.key setting is left unconfigured, allowing any network client to invoke user-creation and access-key-minting RPCs. This grants an unauthenticated attacker full S3 administrative control over the SeaweedFS cluster, and the issue is rated Critical with a CVSS v3.1 base score of 9.8.
Technical details
- Root cause: the
SeaweedIdentityAccessManagementgRPC service exposed on the filer’s gRPC listener lacked per-RPC authentication checks; JWT signing-key configuration was not enforced, and mTLS listener-level ACLs only restrict access at the port level, not per RPC. - Trigger condition: exploitable whenever
jwt.filer_signing.keyis unset insecurity.toml, leaving IAM RPCs (e.g., CreateUser, PutPolicy, CreateAccessKey, DeleteUser) callable without credentials. - Attack vector: network access to the filer’s gRPC port; no authentication or user interaction required.
- Impact: attacker can create users, mint S3 access keys, and obtain administrative control over S3 access on the affected SeaweedFS deployment, impacting confidentiality, integrity, and availability.
Affected software
- SeaweedFS (seaweedfs/seaweedfs) filer versions prior to 4.24
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: upgrade SeaweedFS to version 4.24 or later, which requires a Bearer token signed with the filer’s JWT signing key for all IAM gRPC calls and refuses to register the IAM service if no signing key is configured.
- If unable to patch immediately:
- Restrict network access to the filer’s gRPC port to trusted hosts only.
- Configure
jwt.filer_signing.keyinsecurity.tomlso IAM RPCs require signed Bearer tokens. - Review existing S3 users/access keys for signs of unauthorized creation.

