CVE-2026-33322Patch(minio / minio)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch minio minio systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • minio

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-25)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
minio

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 1Mentions · 2026-03-21: 1Mentions · 2026-03-25: 2Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-25: 203-2003-2103-25
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-201
Patch1
2026-03-211
Disclosure1
2026-03-252
Disclosure1Patch1
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Critical #CVE-2026-33322 and #CVE-2026-33419 affect #MinIO and expose critical weaknesses in OIDC and LDAP authentication mechanisms. Attackers could forge identities or perform brute-force attacks. #Patch#Patch#Patch

    Post summary

    The warning alerts to critical MinIO vulnerabilities affecting OIDC and LDAP authentication, allowing attackers to forge identities or brute‑force them, and notes that patches are available.

    01000201
    7.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33322: MinI... JWT algorithm confusion + known OIDC ClientSecret = instant consoleAdmin escalation across 3+ years of MinIO deployments. #JWTConfusion #MinIO #S3. https://zerodaysignal.com/vulnerability/CVE-2026-33322 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-33322, highlighting JWT algorithm confusion in MinIO that can lead to console‑admin escalation via known OIDC ClientSecrets; it provides the technical details but no PoC, exploit, or patch is offered.

    0000053
    168 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `MinIO` has a JWT Algorithm Confusion vulnerability (CVE-2026-33322) in OIDC authentication. This could lead to authentication bypass. Review OIDC configurations. #MinIO #AuthBypass #Cybersecurity https://www.pulsepatch.io/posts/cve-2026-33322-minio-jwt-algorithm-confusion

    Post summary

    MinIO’s OIDC authentication is vulnerable to JWT Algorithm Confusion, allowing authentication bypass, and the article advises reviewing OIDC configurations to mitigate the risk.

    0000027
    2 followersView on X
  • Vulert@vulert_official
    Patch

    🚨🚨 MinIO CVE-2026-33322: Critical identity token forgery flaw could let attackers forge tokens and access sensitive data. Patch/upgrade ASAP. 🔗 https://vulert.com/vuln-db/CVE-2026-33322 🛡 https://t.co/s99vETkPn0

    Post summary

    The post announces MinIO CVE‑2026‑33322, a critical identity token forgery flaw, and urges users to patch or upgrade immediately.

    0000037
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appminiominio---

Explore more