A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows an attacker who possesses a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively converting a simple upload into a CopyObject operation. This can lead to unauthorized access and copying of any data the original signer is permitted to reach across the entire storage system.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-94368 exposes a critical flaw in NooBaa-core's signature verification logic for AWS S3 presigned URLs using Signature Version 4 (SigV4). The vulnerability allows attackers to bypass authentication controls by adding unsigned x-amz- headers to valid presigned requests—headers that the service silently drops from signature calculation rather than rejecting outright. This affects organizations using NooBaa as a Multicloud Object Gateway, particularly those relying on presigned URLs for secure temporary access to S3 objects. An attacker with a legitimate presigned PUT URL could exploit this to modify object metadata or redirect copy operations, effectively circumventing intended access controls and potentially leading to unauthorized data manipulation or exposure.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's 754 security skills—powered by Claude AI's extended reasoning—would detect the attack patterns underlying this vulnerability through techniques aligned with credential abuse and privilege escalation. A practitioner using Casky would identify suspicious patterns including: requests with added x-amz-* headers not present in the original presigned URL signature, discrepancies between signed and unsigned header sets in S3 access logs, and unexpected object modifications tied to presigned URL usage. Casky's skill set enables detection of improper cryptographic validation (CWE-347) by correlating authentication bypass patterns, abnormal S3 operation sequences, and signature validation anomalies—surfacing these findings as high-confidence alerts that indicate attempted exploitation of presigned URL trust boundaries.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-94368. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation