CRITICAL🇵🇱 Wersja polska

CVE-2026-33322

CVSS 9.2v4.0pub. 2026-03-24upd. 2026-04-08

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

🤖 AI Analysis
How it works

The vulnerability (CWE-287) results from an error in JWT algorithm handling (JWT algorithm confusion) in the OpenID Connect (OIDC) authentication mechanism in MinIO. An attacker with knowledge of the OIDC ClientSecret value can exploit an imprecision in token signature algorithm verification to craft their own identity token accepted by the server as valid. The forged token allows obtaining S3 credentials associated with any arbitrarily chosen access policy.

Impact

The attacker can gain full administrative access to the MinIO instance (consoleAdmin role), which enables reading, modification, and deletion of stored object data as well as takeover of control over the entire storage infrastructure.

Mitigation & patch

MinIO should be updated to version RELEASE.2026-03-17T21-25-16Z or later, in which the vulnerability has been fixed. Additionally, it is worth considering rotation of the OIDC ClientSecret value as a supplementary action after the update.

Who is affected

MinIO in versions from RELEASE.2022-11-08T05-27-07Z to the version preceding RELEASE.2026-03-17T21-25-16Z, with OpenID Connect integration enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Minio

    APP
    Minio
    2022-11-08t05-27-07z – 2026-03-17t21-25-16z (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-33419CRITICAL9.1PL ✓same product

MinIO AIStor: brute-force danych LDAP przez STS AssumeRoleWithLDAPIdentity

CVE-2020-11012CRITICAL9.3PL ✓same product

MinIO: Authentication Bypass w Admin API umożliwiający tworzenie kont

CVE-2023-28434HIGH8.8⚠ KEVsame product

Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use cr...

CVE-2023-28432HIGH7.5⚠ KEVsame product

Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-1...

CVE-2026-40344HIGH8.8same product

MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEA...