CVE-2026-79787: Alluxio

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

Affected products

  • Alluxio Alluxio: up to and including 2.9.5

Published 2026-08-25. Last modified 2026-09-24.