Improper Verification of Cryptographic Signature in Ceph - CVE-2026-54330
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper verification of cryptographic signatures in Ceph RGW\'s SigV4 handler when processing presigned PUT requests. A remote user can attach arbitrary unsigned x-amz-* headers to escalate privileges.
Exploitation requires a presigned PUT URL.