Junglewise Threat Intelligence

CVE-2026-42600: MinIO path traversal in ReadMultiple storage-REST endpoint

CVE-2026-42600 · Severity: medium · CVSS 4.9 · Published 2026-05-11

Technologies: Minio, github.com/minio/minio (Go). Vendors: MinIO, Go.

Executive brief

MinIO, a high-performance object storage service, is vulnerable to a security flaw in its internal communication system. An attacker with administrative credentials can bypass security restrictions to read sensitive files directly from the server's underlying operating system. This could lead to the exposure of private encryption keys, system passwords, and other confidential data, potentially allowing for a full compromise of the host environment.

Technical details

A path traversal vulnerability exists in MinIO's `ReadMultiple` internode storage-REST endpoint due to insufficient validation of the `Bucket` field in msgpack-encoded request bodies. While global middleware filters `..` sequences in URL paths and forms, it does not inspect the msgpack body processed by `cmd/storage-rest-server.go`. An attacker possessing the cluster root JWT (signed with `MINIO_ROOT_PASSWORD`) can use `..` sequences to escape the drive root. The server uses `os.OpenFile` with `O_RDONLY|O_NOATIME` to return file contents. Impact varies by deployment: bare-metal installations are limited to files owned by the MinIO UID, while containerized deployments running as root (UID 0) allow full host filesystem disclosure. The vulnerability was fixed by removing the affected handler in MinIO AIStor RELEASE.2024-10-23T19-38-07Z.

Affected products

  • MinIO MinIO RELEASE.2022-07-24T01-54-52Z through RELEASE.2025-09-07T16-13-09Z

Timeline

  • 2022-07-24: other: Vulnerability introduced in RELEASE.2022-07-24T01-54-52Z
  • 2024-10-23: patched: First patched in MinIO AIStor RELEASE.2024-10-23T19-38-07Z
  • 2026-04-25: disclosed
  • 2026-05-05: advisory

References

Related threats