CVE-2026-33322: 
MinIO vulnerability analysis and mitigation

Overview

CVE-2026-33322 is a JWT algorithm confusion vulnerability in MinIO's OpenID Connect (OIDC) authentication that allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any IAM policy, including consoleAdmin. It affects all MinIO releases from RELEASE.2022-11-08T05-27-07Z through versions prior to RELEASE.2026-03-17T21-25-16Z. The vulnerability was published on March 19, 2026, via GitHub Advisory GHSA-5cx5-wh4m-82fh. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Feedly).

Technical details

The root cause is improper authentication (CWE-287) stemming from a JWT algorithm confusion flaw in MinIO's OIDC authentication flow. When MinIO validates identity tokens received from an OIDC provider, it does not properly enforce the expected JWT signing algorithm, allowing an attacker to craft a token signed using the OIDC ClientSecret (a symmetric HMAC algorithm) instead of the expected asymmetric algorithm used by the identity provider. This bypasses signature verification and allows the attacker to embed arbitrary claims — including any user identity and IAM policy — into the forged token. The attack requires no race conditions and has a 100% deterministic success rate given knowledge of the ClientSecret (GitHub Advisory).

Impact

A successful exploit grants the attacker full administrative control over the MinIO deployment. Specifically, the attacker can impersonate any user identity, obtain S3 credentials with any IAM policy including consoleAdmin, and subsequently access, modify, or delete any data stored in the MinIO instance. The confidentiality, integrity, and availability of all data in the deployment are fully compromised. Because MinIO is commonly used as object storage infrastructure, exploitation could expose sensitive application data, enable data destruction, or facilitate lateral movement into dependent systems (GitHub Advisory, Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.016%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack prerequisite — knowledge of the OIDC ClientSecret — is noted as more accessible than commonly assumed, given prior exposure via CVE-2023-28432 (which leaked MinIO environment variables including MINIO_IDENTITY_OPENID_CLIENT_SECRET), as well as frequent presence in CI/CD pipelines, frontend OAuth configurations, and shared configuration files (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify MinIO deployments configured with OIDC authentication (versions RELEASE.2022-11-08T05-27-07Z through pre-RELEASE.2026-03-17T21-25-16Z) using network scanning tools or by reviewing exposed configuration endpoints.
  2. Obtain the OIDC ClientSecret: Retrieve the MINIO_IDENTITY_OPENID_CLIENT_SECRET value from exposed environment variables (e.g., via CVE-2023-28432), CI/CD pipeline configurations, frontend OAuth app bundles, or shared configuration files accessible to operators.
  3. Craft a forged JWT: Using the ClientSecret as an HMAC signing key, construct a JWT with an algorithm header set to a symmetric algorithm (e.g., HS256) and embed arbitrary claims — including the desired user identity and IAM policy (e.g., consoleAdmin) — in the token payload.
  4. Submit the forged token: Present the crafted JWT to MinIO's OIDC authentication endpoint. Due to the algorithm confusion flaw, MinIO accepts the HMAC-signed token as valid.
  5. Obtain S3 credentials: MinIO issues S3 credentials corresponding to the forged identity and policy, granting the attacker full administrative access to the deployment.
  6. Access or manipulate data: Use the obtained credentials with any S3-compatible client to read, modify, or delete any data in the MinIO deployment (GitHub Advisory, Feedly).

Indicators of compromise

  • Logs: MinIO access logs showing OIDC authentication events with unexpected user identities or policy claims (e.g., consoleAdmin) not associated with legitimate users; authentication events originating from unusual IP addresses or at unusual times.
  • Logs: Presence of S3 API calls (especially ListBuckets, GetObject, DeleteObject, PutObject) immediately following an OIDC token exchange, particularly under admin-level credentials not tied to known user accounts.
  • Network: Outbound connections from the MinIO server to unknown endpoints following authentication events, which may indicate data exfiltration.
  • Configuration: Evidence of the MINIO_IDENTITY_OPENID_CLIENT_SECRET environment variable being accessed or logged in CI/CD systems, container orchestration logs, or application configuration files.
  • Authentication Events: OIDC token exchanges where the JWT algorithm header is HS256 (or another symmetric algorithm) rather than the asymmetric algorithm (RS256, ES256) expected from the configured identity provider (GitHub Advisory).

Mitigation and workarounds

MinIO has released a fix in RELEASE.2026-03-17T21-25-16Z (MinIO AIStor); all open-source minio/minio users should upgrade to this version or later immediately. As a workaround where patching is not immediately feasible, treat the OIDC ClientSecret as a highly sensitive credential: rotate it, restrict access to authorized personnel only, and audit all locations where it may be stored (CI/CD pipelines, configuration files, container environment variables). Additionally, implement network segmentation to limit access to MinIO deployments and monitor OIDC authentication logs for anomalous identity or policy claims (GitHub Advisory, Feedly).

Community reactions

The advisory was published by MinIO maintainer harshavardhana on March 19, 2026, crediting KoreaSecurity Finder as the reporter and donatello, taran-p, and harshavardhana for remediation. The minio/minio open-source repository was subsequently archived by its owner on April 25, 2026, with the fix carried forward into the MinIO AIStor commercial product. The advisory notes the compounding risk from CVE-2023-28432, which previously exposed the ClientSecret via environment variable leakage, highlighting a chain of related security concerns in MinIO's OIDC implementation (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related MinIO vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84445HIGH8.7
  • cAdvisor logocAdvisor
  • helmfile
NoYesSep 14, 2026
CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • eck-operator
NoYesSep 01, 2026
CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • rancher-agent-fips-2.14
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • kubernetes
NoYesSep 02, 2026
CVE-2026-81870LOW2
  • cAdvisor logocAdvisor
  • gitlab-cng-fips-19.3
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management