MinIO Vulnerability Allows Info Disclosure and Security Bypass
Summary
CERT-Bund has issued a security advisory for MinIO, a S3-compatible object storage system. A critical vulnerability (CVSS 9.1) allows remote attackers to disclose information and bypass security measures. The advisory urges users to apply mitigations.
What changed
CERT-Bund has released a critical security advisory (WID-SEC-2026-0812) concerning MinIO, an S3-compatible object storage solution used for large-scale AI/ML, Data Lake, and database workloads. The advisory details a vulnerability that allows remote, anonymous attackers to exploit MinIO to disclose information and bypass security controls. The vulnerability has a CVSS Base Score of 9.1 (critical) and a Temporal Score of 7.9 (high). The affected product is Open Source MinIO, specifically versions prior to RELEASE.2026-03-17T21-25-16Z, running on Linux and UNIX operating systems.
Organizations utilizing MinIO, particularly those handling sensitive data or critical workloads, must immediately review and apply available mitigations to address this critical vulnerability. Failure to do so could result in significant data breaches and compromise of system security. The advisory indicates that mitigations are available, and users should consult the provided links for specific instructions and version history. The advisory was published on March 22, 2026, with an update on March 23, 2026.
What to do next
- Review MinIO version for vulnerability (prior to RELEASE.2026-03-17T21-25-16Z)
- Apply available mitigations for CVE-XXXX-XXXX
- Consult CERT-Bund advisory for specific remediation steps
Source document (simplified)
[WID-SEC-2026-0812] MinIO: Schwachstelle ermöglicht Offenlegung von Informationen und Umgehen von Sicherheitsvorkehrungen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 22.03.2026 Stand 23.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- UNIX
Produktbeschreibung
MinIO ist ein S3-kompatibler Objektspeicher, der für groß angelegte KI/ML-, Data Lake- und Datenbank-Workloads entwickelt wurde. Er läuft "on-premise" und in jeder Cloud.
Produkte
22.03.2026
- Open Source MinIO <AIStor RELEASE.2026-03-17T21-25-16Z
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MinIO ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.