MinIO disclosed two high-severity authentication vulnerabilities that could let attackers obtain unauthorized access to S3 data and administrative functions. CVE-2026-33322 affects OpenID Connect authentication in versions from RELEASE.2022-11-08T05-27-07Z through versions before RELEASE.2026-03-17T21-25-16Z, where a JWT algorithm confusion issue allows an attacker who knows the OIDC ClientSecret to forge identity tokens and obtain S3 credentials with arbitrary policies, including consoleAdmin. The flaw creates a direct path to compromise confidentiality, integrity, and availability across affected MinIO deployments.
A second issue, CVE-2026-33419, affects the STS AssumeRoleWithLDAPIdentity endpoint in MinIO AIStor before RELEASE.2026-03-17T21-25-16Z. Distinct error messages enabled LDAP username enumeration, and the absence of rate limiting allowed unlimited password-guessing attempts by an unauthenticated network attacker. If exploited, the weakness could yield temporary AWS-style STS credentials and expose S3 buckets and objects to unauthorized access. MinIO patched both vulnerabilities in RELEASE.2026-03-17T21-25-16Z.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
New CVE entries were published documenting two high-severity MinIO issues: CVE-2026-33322, which allows forged OIDC identity tokens if the ClientSecret is known, and CVE-2026-33419, which enables LDAP username enumeration and unlimited password guessing for STS credentials.
MinIO patched two authentication vulnerabilities in release RELEASE.2026-03-17T21-25-16Z: an LDAP user-enumeration and brute-force issue in the STS AssumeRoleWithLDAPIdentity endpoint, and a JWT algorithm confusion flaw in OIDC authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.