CVE-2026-50152
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-50152 is an improper authorization vulnerability in the MON (Monitor) subscription handler of Ceph, a distributed storage system. The flaw allows any CephX user holding mon allow r capabilities to read the entire Monitor config-key store by sending a single crafted MMonSubscribe message. Affected versions include Ceph releases prior to 19.2.6 and 20.2.4; patched versions are 19.2.6 and 20.2.4. It carries a CVSS v3.1 base score of 8.2 (High) (Red Hat Advisory, GitHub Advisory). The vulnerability was publicly disclosed on August 19, 2026, with the CVE status listed as Reserved at time of publication (Red Hat Bugzilla).

Technical details

The root cause is a missing authorization check (CWE-862 / CWE-285) in the Ceph Monitor's subscription handler, which fails to enforce access controls when processing MMonSubscribe messages. An attacker with a valid CephX account that has mon allow r capabilities can send a single crafted MMonSubscribe message to the Monitor, causing it to return the full contents of the config-key store without verifying whether the requester is authorized to access that data. Preconditions require the attacker to have network access to the Ceph cluster and a compromised or legitimately obtained account with mon allow r permissions; no user interaction is required (GitHub Advisory, Red Hat Bugzilla). No public proof-of-concept exploit code has been identified at this time (Red Hat Advisory).

Impact

Successful exploitation exposes the entire Monitor config-key store, which contains highly sensitive operational secrets including OSD LUKS disk encryption passphrases and, on cephadm-managed clusters, the SSH private key used to administer every host in the cluster. Exposure of the SSH private key under the default cephadm configuration yields root-level access to all managed hosts, enabling full host compromise and lateral movement across the entire cluster infrastructure. Additionally, access to LUKS passphrases undermines the confidentiality of encrypted data at rest, potentially allowing an attacker to decrypt storage volumes (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (Red Hat Advisory). The vulnerability has been detected by Nessus (plugin ID 338269) and is listed in the Tenable plugin database (Tenable). The attack vector is adjacent network with low attack complexity and low privileges required, making exploitation straightforward for any insider or attacker who has obtained a low-privilege CephX account. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE.

Exploitation steps

  1. Reconnaissance: Identify a target Ceph cluster running a vulnerable version (< 19.2.6 or < 20.2.4) with network access to the Monitor nodes. Determine whether the cluster is managed by cephadm, which increases the impact due to SSH key exposure.
  2. Obtain low-privilege credentials: Acquire or compromise a CephX account that holds mon allow r capabilities — a common permission granted to many Ceph clients and services.
  3. Craft MMonSubscribe message: Construct a crafted MMonSubscribe message targeting the Monitor's subscription handler. The message exploits the missing authorization check to request config-key store contents.
  4. Send message to Monitor: Transmit the crafted message to the Ceph Monitor service from within the cluster network. No user interaction or elevated privileges beyond mon allow r are required.
  5. Extract secrets: Parse the Monitor's response to retrieve the full config-key store contents, including OSD LUKS passphrases and the cephadm SSH private key.
  6. Escalate access: Use the extracted SSH private key to authenticate as root to all cephadm-managed hosts, or use LUKS passphrases to decrypt encrypted OSD volumes, achieving full cluster and host compromise (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Network: Unexpected or anomalous MMonSubscribe messages originating from low-privilege CephX clients directed at Monitor nodes; unusual outbound connections from Monitor or managed hosts following a suspected exploitation event.
  • Logs: Ceph Monitor logs showing config-key store access by accounts that do not normally require such access; audit log entries for mon allow r accounts querying config-key namespaces (e.g., mgr/, cephadm/, osd/).
  • Authentication: SSH login attempts to cluster hosts using the cephadm SSH key from unexpected source IPs or at unusual times; new SSH authorized_keys entries on managed hosts.
  • File System: Unexpected access to or exfiltration of LUKS keyfiles or SSH private key material from Monitor nodes; new files or scripts placed on cephadm-managed hosts consistent with post-exploitation activity.

Mitigation and workarounds

Upgrade Ceph to patched versions 19.2.6 or 20.2.4, which contain the fix for this authorization bypass (GitHub Advisory). As interim workarounds: restrict mon allow r capabilities to only explicitly authorized and trusted CephX users; audit existing CephX capability grants and revoke unnecessary mon allow r permissions. After patching, rotate all potentially exposed secrets — including OSD LUKS passphrases and the cephadm SSH private key — and audit config-key store access logs for signs of prior unauthorized access (Red Hat Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was disclosed via the oss-security mailing list and an OpenStack Security Note (OSSN-0108) was published, indicating awareness within the OpenStack community given Ceph's common use as a backend storage system for OpenStack deployments (oss-sec, OpenStack OSSN). Credit for discovery was given to researchers Greenpepper15 and DavidKorczynski, with mctaggatart coordinating the disclosure (GitHub Advisory). No significant broader social media or media coverage has been identified beyond the official advisory channels at this time.

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-74733NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74732NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74731NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoNoAug 22, 2026
CVE-2026-74730NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026
CVE-2026-74729NONEN/A
  • Linux Debian logoLinux Debian
  • linux
NoYesAug 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management