Privilege Escalation Flaw Discovered in MinIO Service Accounts — CVE-2025-62506
ID: 1f7d5354-1384-5997-82d6-4a002828204b
STIX ID: report--1f7d5354-1384-5997-82d6-4a002828204b
Feed Name: securityonline.info
MinIO published a security advisory for CVE-2025-62506 (CVSS 8.1) describing a privilege escalation bug in IAM policy validation (cmd/iam.go) where the system incorrectly relied on a DenyOnly parameter, allowing restricted service/STS accounts to bypass session policy restrictions and create new service accounts that inherit full parent privileges; the issue was fixed in PR #21642 (commit c1a4949) and administrators are advised to upgrade, audit service accounts, revoke suspicious accounts, and review access logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
