PatchSiren cyber security CVE debrief
CVE-2026-33322 minio CVE debrief
A JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC `ClientSecret` to forge arbitrary identity tokens and obtain S3 credentials with any policy, including `consoleAdmin`. This vulnerability poses significant impersonation and data access risks. Operators and engineers should verify exposure and prioritize remediation. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.
- Vendor
- minio
- Product
- github.com/minio/minio
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-19
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-03-19
- Advisory updated
- 2026-10-08
Who should care
Operators, engineers, and security teams responsible for MinIO deployments should assess exposure and prioritize remediation due to potential impersonation and data access risks. They should verify exposure, restrict access to the OIDC `ClientSecret`, and implement additional authentication and authorization controls to mitigate potential credential theft.
Why it matters
The CVE-2026-33322 vulnerability in MinIO's OpenID Connect authentication allows an attacker to forge arbitrary identity tokens and obtain S3 credentials with any policy, posing significant impersonation and data access risks. Operators and engineers should verify exposure and prioritize remediation.
- Potential impersonation of any user identity
- Theft of S3 credentials with any IAM policy, including `consoleAdmin`
- Access, modification, or deletion of any data in the MinIO deployment
- Verification of MinIO deployment exposure to the OIDC `ClientSecret`
Technical summary
The vulnerability is caused by a JWT algorithm confusion in MinIO's OpenID Connect authentication. An attacker who knows the OIDC `ClientSecret` can forge arbitrary identity tokens and obtain S3 credentials with any policy, including `consoleAdmin`. This allows for impersonation of any user identity, theft of S3 credentials with any IAM policy, and access, modification, or deletion of any data in the MinIO deployment. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.
Defensive priority
Operators and engineers should verify exposure and prioritize remediation due to potential impersonation and data access risks.
Recommended defensive actions
- Verify MinIO deployment exposure to the OIDC `ClientSecret` and assess potential impersonation risks.
- Restrict access to the OIDC `ClientSecret` and monitor for suspicious authentication activity.
- Implement additional authentication and authorization controls to mitigate potential credential theft.
- Review and update MinIO configurations to prevent exploitation.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The vulnerability allows an attacker to impersonate any user identity, obtain S3 credentials with any IAM policy, and access, modify, or delete any data in the MinIO deployment. The attack prerequisites include knowledge of the OIDC `ClientSecret`, which may be more accessible than assumed due to previous leaks and common presence in configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-33322 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-33322
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-33322 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-33322
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MinIO has JWT Algorithm Confusion in OIDC Authentication
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-5cx5-wh4m-82fh.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio/security/advisories/GHSA-5cx5-wh4m-82fh
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.