Redpacketsecurity Critical Flaw in NooBaa Multicloud Gateway Exposes Data to Unauthorized Access
Article Content
- •CVE-2026-94368 allows unauthorized data access via presigned URLs.
- •Attackers can exploit the flaw without needing high privileges.
- •No effective mitigation is currently available from Red Hat.
A significant vulnerability (CVE-2026-94368) has been identified in the noobaa-core component of the NooBaa Multicloud Object Gateway. This flaw affects the processing of S3 presigned URLs using Signature Version 4, allowing attackers with valid presigned PUT URLs to exploit the service by adding unsigned x-amz-copy-source headers. This can convert upload operations into CopyObject requests, enabling unauthorized access to data across the storage system. The Red Hat Product Security team has classified this vulnerability as Important, highlighting the risk of unauthorized data disclosure and potential data manipulation. Currently, no effective mitigation is available, and organizations using the gateway for shared or multi-tenant workloads are particularly vulnerable. The flaw's root cause is improper validation of x-amz- headers in requests. Red Hat has acknowledged the issue and is working on a resolution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Red Hat and CVE-2026-94368 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…