Alluxio S3 proxy skipped signature verification: CVE-2026-79787 rated 9.3
Alluxio's S3 REST proxy failed to verify AWS Signature Version 4 signatures in its default configuration, letting unauthenticated attackers spoof user identities and read, write or delete arbitrary data. The flaw is tracked as CVE-2026-79787 with an NVD base score of 9.3; a fix has been released.
- CVE-2026-79787 carries an NVD base score of 9.3, affecting S3RestUtils.java
- Attackers spoof usernames via an unsigned Authorization header
- Arbitrary data can be read, written or deleted, including service accounts
- Recommended: upgrade, keep the proxy off the internet, audit access logs
Read next
Security