Vulnerability Description
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/Alluxio/alluxio
- https://github.com/Alluxio/alluxio/blob/v2.9.5/core/server/proxy/src/main/java/a
- https://github.com/Alluxio/alluxio/issues/18755
- https://www.vulncheck.com/advisories/alluxio-through-2.9.5-s3-rest-proxy-authent
- https://github.com/Alluxio/alluxio/issues/18755
FAQ
What is CVE-2026-79787?
CVE-2026-79787 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from...
How severe is CVE-2026-79787?
CVE-2026-79787 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-79787?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.