
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50152 is an improper authorization vulnerability in the MON (Monitor) subscription handler of Ceph, a distributed storage system. The flaw allows any CephX user holding mon allow r capabilities to read the entire Monitor config-key store by sending a single crafted MMonSubscribe message. Affected versions include Ceph releases prior to 19.2.6 and 20.2.4; patched versions are 19.2.6 and 20.2.4. It carries a CVSS v3.1 base score of 8.2 (High) (Red Hat Advisory, GitHub Advisory). The vulnerability was publicly disclosed on August 19, 2026, with the CVE status listed as Reserved at time of publication (Red Hat Bugzilla).
The root cause is a missing authorization check (CWE-862 / CWE-285) in the Ceph Monitor's subscription handler, which fails to enforce access controls when processing MMonSubscribe messages. An attacker with a valid CephX account that has mon allow r capabilities can send a single crafted MMonSubscribe message to the Monitor, causing it to return the full contents of the config-key store without verifying whether the requester is authorized to access that data. Preconditions require the attacker to have network access to the Ceph cluster and a compromised or legitimately obtained account with mon allow r permissions; no user interaction is required (GitHub Advisory, Red Hat Bugzilla). No public proof-of-concept exploit code has been identified at this time (Red Hat Advisory).
Successful exploitation exposes the entire Monitor config-key store, which contains highly sensitive operational secrets including OSD LUKS disk encryption passphrases and, on cephadm-managed clusters, the SSH private key used to administer every host in the cluster. Exposure of the SSH private key under the default cephadm configuration yields root-level access to all managed hosts, enabling full host compromise and lateral movement across the entire cluster infrastructure. Additionally, access to LUKS passphrases undermines the confidentiality of encrypted data at rest, potentially allowing an attacker to decrypt storage volumes (GitHub Advisory, Red Hat Bugzilla).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Red Hat Advisory). The vulnerability has been detected by Nessus (plugin ID 338269) and is listed in the Tenable plugin database (Tenable). The attack vector is adjacent network with low attack complexity and low privileges required, making exploitation straightforward for any insider or attacker who has obtained a low-privilege CephX account. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.
mon allow r capabilities — a common permission granted to many Ceph clients and services.MMonSubscribe message targeting the Monitor's subscription handler. The message exploits the missing authorization check to request config-key store contents.mon allow r are required.MMonSubscribe messages originating from low-privilege CephX clients directed at Monitor nodes; unusual outbound connections from Monitor or managed hosts following a suspected exploitation event.mon allow r accounts querying config-key namespaces (e.g., mgr/, cephadm/, osd/).Upgrade Ceph to patched versions 19.2.6 or 20.2.4, which contain the fix for this authorization bypass (GitHub Advisory). As interim workarounds: restrict mon allow r capabilities to only explicitly authorized and trusted CephX users; audit existing CephX capability grants and revoke unnecessary mon allow r permissions. After patching, rotate all potentially exposed secrets — including OSD LUKS passphrases and the cephadm SSH private key — and audit config-key store access logs for signs of prior unauthorized access (Red Hat Advisory, Red Hat Bugzilla).
The vulnerability was disclosed via the oss-security mailing list and an OpenStack Security Note (OSSN-0108) was published, indicating awareness within the OpenStack community given Ceph's common use as a backend storage system for OpenStack deployments (oss-sec, OpenStack OSSN). Credit for discovery was given to researchers Greenpepper15 and DavidKorczynski, with mctaggatart coordinating the disclosure (GitHub Advisory). No significant broader social media or media coverage has been identified beyond the official advisory channels at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."