chiprook
← Security
SecurityOctober 9, 2026, 12:40

Alluxio S3 proxy skipped signature verification: CVE-2026-79787 rated 9.3

Alluxio's S3 REST proxy failed to verify AWS Signature Version 4 signatures in its default configuration, letting unauthenticated attackers spoof user identities and read, write or delete arbitrary data. The flaw is tracked as CVE-2026-79787 with an NVD base score of 9.3; a fix has been released.

Alluxio S3 proxy skipped signature verification: CVE-2026-79787 rated 9.3
#Alluxio
Read next
Security

Adobe Connect: three stored XSS flaws rated 9.3

Security

CVE-2026-67278 in MikroTik RouterOS allows RSA signature forgery

Security

OpenSSH 10.6 released with post-quantum signatures, LZ77 disabled

Security

AWS library stored SQS payloads in S3 unencrypted for 4 years