PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-33322 minio CVE debrief

A JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC `ClientSecret` to forge arbitrary identity tokens and obtain S3 credentials with any policy, including `consoleAdmin`. This vulnerability poses significant impersonation and data access risks. Operators and engineers should verify exposure and prioritize remediation. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.

Vendor
minio
Product
github.com/minio/minio
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-19
Original CVE updated
2026-10-08
Advisory published
2026-03-19
Advisory updated
2026-10-08

Who should care

Operators, engineers, and security teams responsible for MinIO deployments should assess exposure and prioritize remediation due to potential impersonation and data access risks. They should verify exposure, restrict access to the OIDC `ClientSecret`, and implement additional authentication and authorization controls to mitigate potential credential theft.

Why it matters

The CVE-2026-33322 vulnerability in MinIO's OpenID Connect authentication allows an attacker to forge arbitrary identity tokens and obtain S3 credentials with any policy, posing significant impersonation and data access risks. Operators and engineers should verify exposure and prioritize remediation.

  • Potential impersonation of any user identity
  • Theft of S3 credentials with any IAM policy, including `consoleAdmin`
  • Access, modification, or deletion of any data in the MinIO deployment
  • Verification of MinIO deployment exposure to the OIDC `ClientSecret`

Technical summary

The vulnerability is caused by a JWT algorithm confusion in MinIO's OpenID Connect authentication. An attacker who knows the OIDC `ClientSecret` can forge arbitrary identity tokens and obtain S3 credentials with any policy, including `consoleAdmin`. This allows for impersonation of any user identity, theft of S3 credentials with any IAM policy, and access, modification, or deletion of any data in the MinIO deployment. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.

Defensive priority

Operators and engineers should verify exposure and prioritize remediation due to potential impersonation and data access risks.

Recommended defensive actions

  • Verify MinIO deployment exposure to the OIDC `ClientSecret` and assess potential impersonation risks.
  • Restrict access to the OIDC `ClientSecret` and monitor for suspicious authentication activity.
  • Implement additional authentication and authorization controls to mitigate potential credential theft.
  • Review and update MinIO configurations to prevent exploitation.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The vulnerability allows an attacker to impersonate any user identity, obtain S3 credentials with any IAM policy, and access, modify, or delete any data in the MinIO deployment. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-33322 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-33322

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-33322 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33322

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.