Skip to content
Critical Flaw in NooBaa Multicloud Gateway Exposes Data to Unauthorized Access

Critical Flaw in NooBaa Multicloud Gateway Exposes Data to Unauthorized Access

First seen 21 Sep 2026, 16:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 18:54 UTC
  • CVE-2026-94368 allows unauthorized data access via presigned URLs.
  • Attackers can exploit the flaw without needing high privileges.
  • No effective mitigation is currently available from Red Hat.

A significant vulnerability (CVE-2026-94368) has been identified in the noobaa-core component of the NooBaa Multicloud Object Gateway. This flaw affects the processing of S3 presigned URLs using Signature Version 4, allowing attackers with valid presigned PUT URLs to exploit the service by adding unsigned x-amz-copy-source headers. This can convert upload operations into CopyObject requests, enabling unauthorized access to data across the storage system. The Red Hat Product Security team has classified this vulnerability as Important, highlighting the risk of unauthorized data disclosure and potential data manipulation. Currently, no effective mitigation is available, and organizations using the gateway for shared or multi-tenant workloads are particularly vulnerable. The flaw's root cause is improper validation of x-amz- headers in requests. Red Hat has acknowledged the issue and is working on a resolution.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
CVE-2026-94368 published
A flaw in noobaa-core's signature verification logic was disclosed, affecting S3 presigned URLs.
access.redhat.com
2026-09-21
Red Hat assesses vulnerability severity
Red Hat classified the vulnerability as Important due to the ease of exploitation with valid presigned URLs.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Red Hat and CVE-2026-94368 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed