PatchSiren cyber security CVE debrief
CVE-2026-41145 minio CVE debrief
CVE-2026-41145 is an authentication bypass vulnerability in MinIO's STREAMING-UNSIGNED-PAYLOAD-TRAILER code path. This vulnerability allows any user with a valid access key to write arbitrary objects to any bucket without needing the secret key or a valid cryptographic signature. The vulnerability lies in MinIO's handling of unsigned trailer uploads. Specifically, the `PutObjectHandler` and `PutObjectPartHandler` functions call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. An attacker can bypass authentication by omitting the `Authorization` header and supplying credentials exclusively via the `X-Amz-Cred
- Vendor
- minio
- Product
- github.com/minio/minio
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-14
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-04-14
- Advisory updated
- 2026-10-08
Who should care
MinIO administrators, security teams, and developers using MinIO in their applications should assess exposure and take necessary actions to secure their deployments. This includes verifying exposure, restricting access, and planning for remediation. Affected operators, platforms, vulnerability-management teams, and security teams should prioritize verifying and securing MinIO deployments.
Why it matters
CVE-2026-41145 is an authentication bypass vulnerability in MinIO that allows unauthorized object writes. MinIO administrators and security teams should verify exposure, restrict access, and plan for remediation.
- Potential unauthorized data writes to MinIO buckets
- Possible data tampering or corruption
- Increased risk of data breaches
- Need for urgent verification of MinIO deployment security
Technical summary
The vulnerability lies in MinIO's handling of unsigned trailer uploads. Specifically, the `PutObjectHandler` and `PutObjectPartHandler` functions call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. An attacker can bypass authentication by omitting the `Authorization` header and supplying credentials exclusively via the `X-Amz-Credential` query parameter.
Defensive priority
Defenders should prioritize verifying exposure of MinIO deployments, especially those with publicly accessible buckets or using default access keys.
Recommended defensive actions
- Verify MinIO deployments for exposure, especially those with publicly accessible buckets or using default access keys.
- Restrict access to MinIO buckets and ensure secure access keys are in use.
- Monitor for suspicious object writes to MinIO buckets.
- Update MinIO to a version that addresses this vulnerability, once available.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is confirmed in MinIO deployments prior to a specific version. The source corpus provides details on the vulnerability but does not specify the exact version. Defenders should verify exposure of MinIO deployments, especially those with publicly accessible buckets or using default access keys. Evidence is limited to source item descriptions and CVE metadata. Further verification is needed to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41145 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41145
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41145 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41145
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsign
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Go/GHSA-hv4r-mvr4-25vw.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio/security/advisories/GHSA-hv4r-mvr4-25vw
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio/pull/16484
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio/commit/76913a9fd5c6e5c2dbd4e8c7faf56ed9e9e24091
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/minio/minio
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.