← All Advisories

CVE-2026-94368

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-94368

Key Details

CVECVE-2026-94368
CVSS Score / Version7.1 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is low; availability impact is none.
Affected productsRed Hat Red Hat Openshift Data Foundation 4
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Openshift Data Foundation 4
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows an attacker who possesses a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively converting a simple upload into a CopyObject operation. This can lead to unauthorized access and copying of any data the original signer is permitted to reach across the entire storage system. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-94368
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-94368