Database/Control plane, storage & DevOps
MinIO (service accounts / STS session policies): The session policy attached to a service account or STS credential is
Impact
The session policy attached to a service account or STS credential is not enforced, so a credential that was deliberately scoped down to one prefix operates with the full rights of its parent identity. A key you handed a tenant job expecting it to see one bucket can read and write everything the parent can.
Who can reach it
Any holder of a MinIO service account or STS credential - typically every tenant workload, since scoped-down keys are the normal way to hand out access.
What to do
Upgrade MinIO to the release in GHSA-jjjj-jwhf-8rgr and restart. Then re-issue every service account and STS credential that relied on a session policy for isolation, and back the boundary with distinct parent users per tenant rather than session policies alone.
References
Related entries
- Apache CloudStack: MinIO policies survive bucket deletion, giving a former owner access to a new bucket of the same nameCVE-2025-66467 · Apache CloudStack (MinIO object store policy cleanup on bucket deletion)High
- N-able N-central: Incomplete patch for CVE-2026-18556CVE-2026-18577 · N-able N-centralHigh
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsCVE-2026-22719 · VMware Aria Operations (command injection during assisted migration)High
- OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location hostCVE-2026-51773 · OpenStack glance_store (VMware datastore driver, _retry_request)High
- Ceph RGW: unsigned x-amz-* headers on presigned URLs are honored, letting a URL holder escalate privilegesCVE-2026-54330 · Ceph Object Gateway (RGW SigV4 presigned-URL header validation)High
- Apache Airflow Git provider: SSH host-key verification disabled by default when cloning DAG bundlesCVE-2026-58065 · Apache Airflow Git provider (apache-airflow-providers-git, git-over-SSH host key checking)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.