CVE-2026-94368: Improper Verification of Cryptographic Signature in Red Hat Red Hat Openshift Data Foundation 4
CVE-2026-94368 is a vulnerability in the signature verification logic of noobaa-core, a component of Red Hat Openshift Data Foundation 4. It affects the processing of S3 presigned URLs using Signature Version 4 (SigV4). The flaw allows an attacker with a valid presigned PUT URL to add an unsigned x-amz-copy-source header, converting an upload into a CopyObject operation. This can lead to unauthorized access and copying of data accessible to the original signer. The vulnerability has a high severity rating with a CVSS score of 7.1. Red Hat manages remediation for this cloud-hosted service, and a fix is available. No effective mitigations currently meet Red Hat's criteria for ease of use and deployment.
AI Analysis
Technical Summary
The vulnerability in noobaa-core arises from improper validation of x-amz- headers in SigV4 presigned URL requests. Specifically, the service fails to reject requests containing unsigned x-amz- headers, dropping them from the signature calculation instead. This allows an attacker possessing a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively escalating the operation to CopyObject. This flaw enables unauthorized copying of any data the original signer can access across the storage system. The root cause is the failure to enforce inclusion of all x-amz- headers in the cryptographic signature, violating proper signature verification principles. The vulnerability is rated important/high severity by Red Hat with a CVSS 3.1 score of 7.1 (Network attack vector, low complexity, low privileges required, no user interaction, unchanged scope, high confidentiality impact, low integrity impact, no availability impact).
Potential Impact
Successful exploitation allows an attacker with a valid presigned URL to bypass intended access controls and read or overwrite any data accessible to the signer of the URL. This can lead to unauthorized data copying across the entire storage system managed by Red Hat Openshift Data Foundation 4. The confidentiality impact is high, integrity impact is low, and availability is unaffected.
Mitigation Recommendations
Red Hat manages remediation for this cloud-hosted service and has confirmed that a patch is available. However, currently available mitigations do not meet Red Hat's criteria for ease of use, applicability, or stability. Users should monitor the Red Hat advisory for updates and apply the official fix once released. No alternative mitigations are recommended by Red Hat at this time.
CVE-2026-94368: Improper Verification of Cryptographic Signature in Red Hat Red Hat Openshift Data Foundation 4
Description
CVE-2026-94368 is a vulnerability in the signature verification logic of noobaa-core, a component of Red Hat Openshift Data Foundation 4. It affects the processing of S3 presigned URLs using Signature Version 4 (SigV4). The flaw allows an attacker with a valid presigned PUT URL to add an unsigned x-amz-copy-source header, converting an upload into a CopyObject operation. This can lead to unauthorized access and copying of data accessible to the original signer. The vulnerability has a high severity rating with a CVSS score of 7.1. Red Hat manages remediation for this cloud-hosted service, and a fix is available. No effective mitigations currently meet Red Hat's criteria for ease of use and deployment.
CVSS v3.1
Score 7.1high
Affected software
Red Hat
Red Hat Openshift Data Foundation 4
Red Hat
Red Hat Openshift Data Foundation 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in noobaa-core arises from improper validation of x-amz- headers in SigV4 presigned URL requests. Specifically, the service fails to reject requests containing unsigned x-amz- headers, dropping them from the signature calculation instead. This allows an attacker possessing a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively escalating the operation to CopyObject. This flaw enables unauthorized copying of any data the original signer can access across the storage system. The root cause is the failure to enforce inclusion of all x-amz- headers in the cryptographic signature, violating proper signature verification principles. The vulnerability is rated important/high severity by Red Hat with a CVSS 3.1 score of 7.1 (Network attack vector, low complexity, low privileges required, no user interaction, unchanged scope, high confidentiality impact, low integrity impact, no availability impact).
Potential Impact
Successful exploitation allows an attacker with a valid presigned URL to bypass intended access controls and read or overwrite any data accessible to the signer of the URL. This can lead to unauthorized data copying across the entire storage system managed by Red Hat Openshift Data Foundation 4. The confidentiality impact is high, integrity impact is low, and availability is unaffected.
Mitigation Recommendations
Red Hat manages remediation for this cloud-hosted service and has confirmed that a patch is available. However, currently available mitigations do not meet Red Hat's criteria for ease of use, applicability, or stability. Users should monitor the Red Hat advisory for updates and apply the official fix once released. No alternative mitigations are recommended by Red Hat at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-21T11:13:36.872Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-94368","vendor":"Red Hat"}]
Threat ID: 6ab1abbb55bf5e2cf58b4684
Added to database: 09/21/2026, 22:12:11 UTC
Last enriched: 09/21/2026, 22:14:24 UTC
Last updated: 09/22/2026, 00:48:02 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.