Database/Control plane, storage & DevOps
MinIO (admin IAM import API): The IAM import API can be driven to grant an attacker administrative policy, converting a
Impact
The IAM import API can be driven to grant an attacker administrative policy, converting a low-privileged or unauthenticated position into full control of users, policies and every bucket in the deployment. That is total collapse of the tenancy model on the object store.
Who can reach it
Reachable against the MinIO admin API endpoint over the network.
What to do
Upgrade to RELEASE.2024-12-18T13-15-44Z or later and restart all nodes. Then dump the IAM configuration and diff it against your intended state, remove any policy attachments you did not create, and rotate root and admin credentials.
References
Related entries
- Renovate: shell metacharacters in helmv3 registryAliases give commit-access users command executionCVE-2024-58376 · Renovate (helmv3 manager, registryAliases handling)Critical
- Citrix NetScaler ADC and Gateway: unauthenticated remote compromise of the applianceCVE-2026-19490 · Citrix NetScaler ADC / GatewayCritical
- Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UI: The optional web UI exposes a training controlCVE-2026-48797 · Backpropagate (single-GPU LLM fine-tuning library) - Reflex web UICritical
- Assisted Migration Agent (hardcoded insecure TLS to vCenter): The agent hardcodes insecure TLS when talking to vCenterCVE-2026-53475 · Assisted Migration Agent (hardcoded insecure TLS to vCenter)Critical
- Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointersCVE-2026-72329 · Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table)Critical
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCVE-2026-80238 · Dell Secure Connect Gateway 5.0 (orchestrator container / exposed Docker socket)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.