Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-79787: Alluxio allows attackers to impersonate users and access data

CVE-2026-79787 · published 9 days ago
Summary

Alluxio’s built‑in gateway for cloud storage does not check that incoming requests really come from an authorized source when left in its default setup. This lets anyone pretend to be any user, including service accounts, and read, change, or delete any stored files. Fix the issue by applying the latest Alluxio update and configuring the gateway to require proper authentication for all requests.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
alluxio alluxio <= 2.9.5
Original advisory text
Alluxio through 2.9.5 S3 REST Proxy Authentication Bypass via Unverified Request Signature
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-287Improper Authentication
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Sources
CVE-2026-79787 · MITRE
Monitor software like this
Free during beta