logo

High-Severity Authentication Bypass Discovered in MinIO Storage

ID: 67c5f5f7-7001-5469-a246-0ead38460551

STIX ID: report--67c5f5f7-7001-5469-a246-0ead38460551

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVSS 8.8) in MinIO's STREAMING-UNSIGNED-PAYLOAD-TRAILER code path allows attackers who possess a valid access key to bypass signature verification by omitting the Authorization header and supplying credentials via X-Amz-Credential, enabling unauthorized object writes (including multipart uploads). The flaw affects open-source releases since May 2023 and is resolved in MinIO AIStor RELEASE.2026-04-11T03-20-12Z; mitigations include immediate upgrade, WAF/reverse-proxy filtering for X-Amz-Content-Sha256:STREAMING-UNSIGNED-PAYLOAD-TRAILER, and tightening s3:PutObject permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.