CVE-2026-33322

CRITICAL

MinIO: JWT Algorithm Confusion in OIDC Authentication

Title source: cna
STIX 2.1

Description

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

Scores

CVSS v3 9.8
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (3)
minio/minio 0Go
minio/minio 2022-11-08t05-27-07z - 2026-03-17t21-25-16z
minio/minio >= RELEASE.2022-11-08T05-27-07Z, < RELEASE.2026-03-17T21-25-16Z
Published Mar 24, 2026
Tracked Since Mar 25, 2026