PatchSiren cyber security CVE debrief
CVE-2026-39944 ceph CVE debrief
The RADOS Gateway (RGW) in Ceph versions prior to 20.2.4 and 19.2.6 uses an insecure AES-128-CBC handler to protect STS session tokens, lacking message authentication. This allows attackers to tamper with tokens undetected, escalating to full RGW administrative access. The attack is reachable remotely over the RGW S3 endpoint and requires only a single valid STS token with STS enabled. Ceph administrators should review their deployments for exposure and apply patches or mitigations as needed.
- Vendor
- ceph
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-09-01
Who should care
Ceph administrators, users of Ceph RADOS Gateway, security teams monitoring for remote code execution and privilege escalation vulnerabilities in storage platforms, and operators responsible for maintaining Ceph deployments should be aware of this vulnerability and take necessary actions to mitigate the risk. This includes reviewing their deployments for exposure, applying patches or mitigations, and monitoring for suspicious activity. Additionally, security teams should consider the potential impact on their organization's assets and prioritize patching accordingly. IT teams responsible for Ceph maintenance should also be informed about the vulnerability and its potential impact on their systems. Furthermore, vulnerability management teams should ensure that affected deployments are identified and prioritized for patching. Lastly, incident response teams should be prepared to respond to potential exploitation attempts. The vulnerability's impact on Ceph deployments necessitates prompt attention from these groups to prevent potential security breaches. Security teams should also consider the vulnerability's severity and CVSS score when prioritizing patching efforts. Affected organizations should also review their incident response plans to ensure they are prepared to respond to potential exploitation attempts. The vulnerability's remote exploitability and potential for privilege escalation make it a high-priority issue for Ceph administrators and security teams. Therefore, it is essential for these groups to collaborate to mitigate the risk associated with this vulnerability. By working together, they can ensure that affected deployments are patched or mitigated, reducing the risk of a security breach. In addition to patching, organizations should also consider implementing compensating controls, such as monitoring and detection, to help identify potential exploitation attempts. By taking a proactive approach to mitigating this vulnerability, organizations can reduce the risk associated with it and protect their Ceph deployments from potential security breaches. Ceph administrators and security teams should also review their current security controls and ensure,
Technical summary
The RADOS Gateway (RGW) in Ceph versions prior to 20.2.4 and 19.2.6 uses an insecure AES-128-CBC handler to protect STS session tokens, lacking message authentication. This allows attackers to tamper with tokens undetected, escalating to full RGW administrative access. The attack is reachable remotely over the RGW S3 endpoint and requires only a single valid STS token with STS enabled. Affected Ceph deployments should prioritize patching to prevent potential privilege escalation.
Defensive priority
This vulnerability allows remote attackers to escalate privileges to full RGW administrative access with a valid STS token. Immediate patching is recommended.
Recommended defensive actions
- Apply patches in versions 20.2.4 and 19.2.6 or later
- Restrict access to the RGW S3 endpoint
- Monitor for suspicious STS token usage
- Consider disabling STS or rotating existing tokens
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The RADOS Gateway (RGW) in Ceph versions prior to 20.2.4 and 19.2.6 uses an insecure AES-128-CBC handler to protect STS session tokens, lacking message authentication. This allows attackers to tamper with tokens undetected, escalating to full RGW administrative access. The attack is reachable remotely over the RGW S3 endpoint and requires only a single valid STS token with STS enabled.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39944 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39944
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39944 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39944
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/ceph/ceph/releases/tag/v19.2.6
-
Source reference
Unverified legacy reference
URL: https://github.com/ceph/ceph/releases/tag/v20.2.4
-
Source reference
Unverified legacy reference
URL: https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.