
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33322 is a JWT algorithm confusion vulnerability in MinIO's OpenID Connect (OIDC) authentication that allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any IAM policy, including consoleAdmin. It affects all MinIO releases from RELEASE.2022-11-08T05-27-07Z through versions prior to RELEASE.2026-03-17T21-25-16Z. The vulnerability was published on March 19, 2026, via GitHub Advisory GHSA-5cx5-wh4m-82fh. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Feedly).
The root cause is improper authentication (CWE-287) stemming from a JWT algorithm confusion flaw in MinIO's OIDC authentication flow. When MinIO validates identity tokens received from an OIDC provider, it does not properly enforce the expected JWT signing algorithm, allowing an attacker to craft a token signed using the OIDC ClientSecret (a symmetric HMAC algorithm) instead of the expected asymmetric algorithm used by the identity provider. This bypasses signature verification and allows the attacker to embed arbitrary claims — including any user identity and IAM policy — into the forged token. The attack requires no race conditions and has a 100% deterministic success rate given knowledge of the ClientSecret (GitHub Advisory).
A successful exploit grants the attacker full administrative control over the MinIO deployment. Specifically, the attacker can impersonate any user identity, obtain S3 credentials with any IAM policy including consoleAdmin, and subsequently access, modify, or delete any data stored in the MinIO instance. The confidentiality, integrity, and availability of all data in the deployment are fully compromised. Because MinIO is commonly used as object storage infrastructure, exploitation could expose sensitive application data, enable data destruction, or facilitate lateral movement into dependent systems (GitHub Advisory, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.016%, reflecting low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack prerequisite — knowledge of the OIDC ClientSecret — is noted as more accessible than commonly assumed, given prior exposure via CVE-2023-28432 (which leaked MinIO environment variables including MINIO_IDENTITY_OPENID_CLIENT_SECRET), as well as frequent presence in CI/CD pipelines, frontend OAuth configurations, and shared configuration files (GitHub Advisory).
RELEASE.2022-11-08T05-27-07Z through pre-RELEASE.2026-03-17T21-25-16Z) using network scanning tools or by reviewing exposed configuration endpoints.MINIO_IDENTITY_OPENID_CLIENT_SECRET value from exposed environment variables (e.g., via CVE-2023-28432), CI/CD pipeline configurations, frontend OAuth app bundles, or shared configuration files accessible to operators.HS256) and embed arbitrary claims — including the desired user identity and IAM policy (e.g., consoleAdmin) — in the token payload.consoleAdmin) not associated with legitimate users; authentication events originating from unusual IP addresses or at unusual times.ListBuckets, GetObject, DeleteObject, PutObject) immediately following an OIDC token exchange, particularly under admin-level credentials not tied to known user accounts.MINIO_IDENTITY_OPENID_CLIENT_SECRET environment variable being accessed or logged in CI/CD systems, container orchestration logs, or application configuration files.HS256 (or another symmetric algorithm) rather than the asymmetric algorithm (RS256, ES256) expected from the configured identity provider (GitHub Advisory).MinIO has released a fix in RELEASE.2026-03-17T21-25-16Z (MinIO AIStor); all open-source minio/minio users should upgrade to this version or later immediately. As a workaround where patching is not immediately feasible, treat the OIDC ClientSecret as a highly sensitive credential: rotate it, restrict access to authorized personnel only, and audit all locations where it may be stored (CI/CD pipelines, configuration files, container environment variables). Additionally, implement network segmentation to limit access to MinIO deployments and monitor OIDC authentication logs for anomalous identity or policy claims (GitHub Advisory, Feedly).
The advisory was published by MinIO maintainer harshavardhana on March 19, 2026, crediting KoreaSecurity Finder as the reporter and donatello, taran-p, and harshavardhana for remediation. The minio/minio open-source repository was subsequently archived by its owner on April 25, 2026, with the fix carried forward into the MinIO AIStor commercial product. The advisory notes the compounding risk from CVE-2023-28432, which previously exposed the ClientSecret via environment variable leakage, highlighting a chain of related security concerns in MinIO's OIDC implementation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."