CVE-2020-11012
MinIO vulnerability analysis and mitigation

Overview

CVE-2020-11012 affects MinIO versions before RELEASE.2020-04-23T00-58-49Z, involving an authentication bypass vulnerability in the MinIO admin API. The vulnerability was discovered during an internal security audit and was disclosed on April 23, 2020. The issue affects MinIO server installations from version RELEASE.2019-12-17T23-16-33Z up to versions before RELEASE.2020-04-23T00-58-49Z (MinIO Advisory).

Technical details

The vulnerability allows authentication bypass in the MinIO admin API where, given an admin access key, it was possible to perform admin API operations without knowing the admin secret key. The issue received a CVSS v3.1 base score of 9.3 CRITICAL from GitHub and 7.5 HIGH from NVD, indicating its severe nature. The vulnerability is classified under CWE-305 (Authentication Bypass by Primary Weakness) and CWE-755 (Improper Handling of Exceptional Conditions) (NVD).

Impact

The vulnerability allows unauthorized users with knowledge of an admin access key to perform administrative operations without requiring the corresponding secret key. This includes the ability to create new service accounts for existing access keys, potentially leading to unauthorized access and control over the MinIO deployment (MinIO Advisory).

Exploitability

The vulnerability was discovered during an internal security audit, and according to the MinIO security advisory, there were no observations of this exploit being used in the wild or reported elsewhere in the community at large (MinIO Advisory).

Mitigation and workarounds

The vulnerability was patched in version RELEASE.2020-04-23T00-58-49Z. Users are advised to upgrade immediately to this version or later. The fix was implemented through PR #9422, which addressed the missing return in admin requests authentication. The patch is available through various distribution channels including direct binary downloads for different platforms and Docker container images (MinIO Advisory).

Additional resources


SourceThis report was generated using AI

Related MinIO vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56862HIGH7.5
  • cAdvisor logocAdvisor
  • elastic-otel-collector-9.4
NoYesAug 13, 2026
CVE-2026-56859HIGH7.5
  • cAdvisor logocAdvisor
  • aws-ebs-csi-driver
NoYesAug 13, 2026
CVE-2026-56853HIGH7.5
  • cAdvisor logocAdvisor
  • dapr-1.17
NoYesAug 13, 2026
CVE-2026-56858MEDIUM6.1
  • cAdvisor logocAdvisor
  • git-lfs-fips
NoYesAug 13, 2026
CVE-2026-56860MEDIUM5.9
  • cAdvisor logocAdvisor
  • flux-image-automation-controller
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management