Junglewise Threat Intelligence

CVE-2025-30156: Ceph CephX authentication credential forgery via unauthenticated encryption

CVE-2025-30156 · Severity: high · CVSS 8.9 · Published 2026-08-28

Technologies: Ceph. Vendors: Ceph.

Executive brief

Ceph is a distributed storage platform used by organizations to store and manage large volumes of data across multiple servers. A weakness in Ceph's authentication protocol allows attackers with network visibility and low-level access to forge administrator credentials, bypass access controls, and potentially gain complete control over the storage cluster and all data within it.

Technical details

The CephX authentication protocol in Ceph versions before 20.2.4 and 19.2.6 uses AES-128-CBC encryption with a hard-coded initialization vector (IV) and no message authentication code (MAC) to protect authentication tickets. This allows multiple attacks: (1) credential forgery via an encryption oracle attack—an attacker observing encrypted tickets can splice ciphertext blocks to create valid tickets for privileged entities like Manager, MDS, and OSD nodes; (2) privilege escalation by flipping a single bit in an encrypted ticket to set the allow_all flag, granting unrestricted cluster access. The attack requires network access to observe CephX traffic and possession of at least one low-privilege CephX key. Patches are available in Ceph 20.2.4 and 19.2.6, which add support for authenticated encryption using AES-256-HMAC-384 (RFC 8009).

Affected products

  • Ceph Ceph before 20.2.4 and 19.2.6

Timeline

  • 2026-08-28: disclosed: CVE-2025-30156 published
  • 2026: patched: Fixed in Ceph 20.2.4 and 19.2.6

References

Related threats