OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94368

HIGH · CVSS 7.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability in the signature verification logic of the NooBaa Multicloud Object Gateway allows attackers to exploit improperly validated S3 presigned URLs. By adding an unsigned x-amz-copy-source header to a valid presigned PUT URL, an attacker can escalate their permissions and perform unauthorized CopyObject operations, potentially accessing and copying sensitive data. Organizations using NooBaa should prioritize addressing this issue to safeguard their storage systems from unauthorized data manipulation.

CVE
CVE-2026-94368
Severity
HIGH
CVSS
7.1
EPSS
0.23%

Original NVD Description

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows an attacker who possesses a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively converting a simple upload into a CopyObject operation. This can lead to unauthorized access and copying of any data the original signer is permitted to reach across the entire storage system.