PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41145 minio CVE debrief

CVE-2026-41145 is an authentication bypass vulnerability in MinIO's STREAMING-UNSIGNED-PAYLOAD-TRAILER code path. This vulnerability allows any user with a valid access key to write arbitrary objects to any bucket without needing the secret key or a valid cryptographic signature. The vulnerability lies in MinIO's handling of unsigned trailer uploads. Specifically, the `PutObjectHandler` and `PutObjectPartHandler` functions call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. An attacker can bypass authentication by omitting the `Authorization` header and supplying credentials exclusively via the `X-Amz-Cred

Vendor
minio
Product
github.com/minio/minio
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-14
Original CVE updated
2026-10-08
Advisory published
2026-04-14
Advisory updated
2026-10-08

Who should care

MinIO administrators, security teams, and developers using MinIO in their applications should assess exposure and take necessary actions to secure their deployments. This includes verifying exposure, restricting access, and planning for remediation. Affected operators, platforms, vulnerability-management teams, and security teams should prioritize verifying and securing MinIO deployments.

Why it matters

CVE-2026-41145 is an authentication bypass vulnerability in MinIO that allows unauthorized object writes. MinIO administrators and security teams should verify exposure, restrict access, and plan for remediation.

  • Potential unauthorized data writes to MinIO buckets
  • Possible data tampering or corruption
  • Increased risk of data breaches
  • Need for urgent verification of MinIO deployment security

Technical summary

The vulnerability lies in MinIO's handling of unsigned trailer uploads. Specifically, the `PutObjectHandler` and `PutObjectPartHandler` functions call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. An attacker can bypass authentication by omitting the `Authorization` header and supplying credentials exclusively via the `X-Amz-Credential` query parameter.

Defensive priority

Defenders should prioritize verifying exposure of MinIO deployments, especially those with publicly accessible buckets or using default access keys.

Recommended defensive actions

  • Verify MinIO deployments for exposure, especially those with publicly accessible buckets or using default access keys.
  • Restrict access to MinIO buckets and ensure secure access keys are in use.
  • Monitor for suspicious object writes to MinIO buckets.
  • Update MinIO to a version that addresses this vulnerability, once available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is confirmed in MinIO deployments prior to a specific version. The source corpus provides details on the vulnerability but does not specify the exact version. Defenders should verify exposure of MinIO deployments, especially those with publicly accessible buckets or using default access keys. Evidence is limited to source item descriptions and CVE metadata. Further verification is needed to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41145 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41145

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41145 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41145

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.