logo

AttachMe: critical OCI vulnerability allows unauthorized access to customer cloud storage volumes

ID: e4033710-a932-5b80-bbef-4754a4c9dcec

STIX ID: report--e4033710-a932-5b80-bbef-4754a4c9dcec

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2022-09-20

Date Updated: 2026-05-01

...
...

Wiz discovered and responsibly disclosed a critical OCI vulnerability named "AttachMe" that permitted cross-tenant attachment of block and boot volumes using only the volume OCID, enabling read/write access, data exfiltration, and potential code execution; Oracle patched the flaw within 24 hours and no customer action was required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.