CVE-2026-33322 Details
Description
MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.
A JWT algorithm confusion vulnerability has been identified in MinIO's OpenID Connect authentication, affecting versions from RELEASE.2022-11-08T05-27-07Z prior to RELEASE.2026-03-17T21-25-16Z. This vulnerability allows an attacker who knows the OIDC ClientSecret to forge identity tokens and obtain S3 credentials with any policy, including consoleAdmin. The issue arises because the OIDC ClientSecret, a shared credential, can be accessed more easily than expected, and was even leaked in a previous CVE. Exploitation of this vulnerability could lead to unauthorized access and manipulation of data within the MinIO deployment.
Users of the open-source 'minio/minio' project should upgrade to MinIO AIStor 'RELEASE.2026-03-17T21-25-16Z' or later. As a workaround, treat the OIDC ClientSecret as a sensitive credential and avoid exposing it to untrusted parties.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/minio/minio/security/advisories/GHSA-5cx5-wh4m-82fh | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| minio minio | >= 2022-11-08t05-27-07z, < 2026-03-17t21-25-16z |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | Initial Analysis | [email protected] |
| Mar 24, 2026 | New CVE Received | [email protected] |