High-Severity Authentication Bypass Discovered in MinIO Storage
ID: 67c5f5f7-7001-5469-a246-0ead38460551
STIX ID: report--67c5f5f7-7001-5469-a246-0ead38460551
Feed Name: securityonline.info
A critical vulnerability (CVSS 8.8) in MinIO's STREAMING-UNSIGNED-PAYLOAD-TRAILER code path allows attackers who possess a valid access key to bypass signature verification by omitting the Authorization header and supplying credentials via X-Amz-Credential, enabling unauthorized object writes (including multipart uploads). The flaw affects open-source releases since May 2023 and is resolved in MinIO AIStor RELEASE.2026-04-11T03-20-12Z; mitigations include immediate upgrade, WAF/reverse-proxy filtering for X-Amz-Content-Sha256:STREAMING-UNSIGNED-PAYLOAD-TRAILER, and tightening s3:PutObject permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
