Database/Control plane, storage & DevOps

BeeGFS (beegfs-ctl / metadata server): Authentication bypass by talking directly to a BeeGFS metadata server. BeeGFS is
Impact
Authentication bypass by talking directly to a BeeGFS metadata server. BeeGFS is a common choice for AI-training scratch storage because it is fast and easy to stand up, and its threat model assumes the storage network is private. Anyone who reaches the metadata server can act against the filesystem's metadata — which means other tenants' namespaces on a shared BeeGFS deployment.
Who can reach it
Network access to a BeeGFS metadata server. The advisory notes such servers are typically not exposed externally — but inside a GPU cluster, 'not externally exposed' still means reachable by every tenant workload on the storage VLAN.
What to do
Upgrade BeeGFS past 7.1.3 and enable connection authentication (the shared-secret connAuthFile), then restart the metadata, storage and client services — a coordinated restart that stalls I/O, so drain jobs first. Enabling connAuth is the load-bearing step; the version upgrade alone does not help if authentication stays off.
References
Related entries
- Dell OpenManage Enterprise (remote code execution): Remote code execution on the OpenManage Enterprise consoleCVE-2021-21596 · Dell OpenManage Enterprise (remote code execution)Critical
- Tailscale (Windows client): Local API bound to a TCP socketCVE-2022-41924 · Tailscale (Windows client)Critical
- GitLab: Attacker can trigger a CI pipeline as another userCVE-2024-6385 · GitLabCritical
- AAP Controller: testing a Vault credential sends the controller pod's service account token to an attacker URLCVE-2026-12564 · Red Hat Ansible Automation Platform Controller (awx_plugins HashiCorp Vault credential plugin)Critical
- Termix: any authenticated user can read other users' stored SSH and sudo passwordsCVE-2026-53548 · Termix (GET /host/db/host/:id/password credential endpoint)Critical
- Progress LoadMaster (ADC): OS command injection in the APICVE-2026-8037 · Progress LoadMaster (ADC)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.