CVE-2026-79787 – Alluxio

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“A forged S3 identity can turn unauthenticated access into full control over stored data.”

Alluxio contains a Critical authentication bypass in its S3 REST proxy. CVE-2026-79787 allows an unauthenticated attacker to spoof AWS Signature Version 4 identity information, impersonate arbitrary users or service accounts, and read, modify, or delete data. The CVSS score is 9.8, which is Critical severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.