LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-79787

Published
CVSS9.8
Severitycritical
WeaknessCWE-287
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-79787

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-79787.