Changeflow GovPing Data Privacy & Cybersecurity MinIO Vulnerability Allows Info Disclosure and ...
Urgent Notice Added Final

MinIO Vulnerability Allows Info Disclosure and Security Bypass

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 22nd, 2026
Detected March 23rd, 2026
Email

Summary

CERT-Bund has issued a security advisory for MinIO, a S3-compatible object storage system. A critical vulnerability (CVSS 9.1) allows remote attackers to disclose information and bypass security measures. The advisory urges users to apply mitigations.

What changed

CERT-Bund has released a critical security advisory (WID-SEC-2026-0812) concerning MinIO, an S3-compatible object storage solution used for large-scale AI/ML, Data Lake, and database workloads. The advisory details a vulnerability that allows remote, anonymous attackers to exploit MinIO to disclose information and bypass security controls. The vulnerability has a CVSS Base Score of 9.1 (critical) and a Temporal Score of 7.9 (high). The affected product is Open Source MinIO, specifically versions prior to RELEASE.2026-03-17T21-25-16Z, running on Linux and UNIX operating systems.

Organizations utilizing MinIO, particularly those handling sensitive data or critical workloads, must immediately review and apply available mitigations to address this critical vulnerability. Failure to do so could result in significant data breaches and compromise of system security. The advisory indicates that mitigations are available, and users should consult the provided links for specific instructions and version history. The advisory was published on March 22, 2026, with an update on March 23, 2026.

What to do next

  1. Review MinIO version for vulnerability (prior to RELEASE.2026-03-17T21-25-16Z)
  2. Apply available mitigations for CVE-XXXX-XXXX
  3. Consult CERT-Bund advisory for specific remediation steps

Source document (simplified)

[WID-SEC-2026-0812] MinIO: Schwachstelle ermöglicht Offenlegung von Informationen und Umgehen von Sicherheitsvorkehrungen CVSS Base Score 9.1 (kritisch) CVSS Temporal Score 7.9 (hoch) Remoteangriff ja Datum 22.03.2026 Stand 23.03.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX

Produktbeschreibung

MinIO ist ein S3-kompatibler Objektspeicher, der für groß angelegte KI/ML-, Data Lake- und Datenbank-Workloads entwickelt wurde. Er läuft "on-premise" und in jeder Cloud.

Produkte

22.03.2026
- Open Source MinIO <AIStor RELEASE.2026-03-17T21-25-16Z

Angriff

Angriff

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MinIO ausnutzen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 22nd, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-0812

Who this affects

Applies to
Employers Technology companies
Industry sector
3341 Computer & Electronics Manufacturing 5182 Data Processing & Hosting
Activity scope
Data Storage Security Controls
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Data Security Information Disclosure

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.