CVE-2026-41145 Details
Description
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path allows any user who knows a valid access key to write arbitrary objects to any bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment is impacted. The attack requires only a valid access key (the well-known default `minioadmin`, or any key with WRITE permission on a bucket) and a target bucket name. `PutObjectHandler` and `PutObjectPartHandler` call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. Meanwhile, `isPutActionAllowed` extracts credentials from either the `Authorization` header or the `X-Amz-Credential` query parameter, and trusts whichever it finds. An attacker omits the `Authorization` header and supplies credentials exclusively via the query string. The signature gate evaluates to `false`, `doesSignatureMatch` is never called, and the request proceeds with the permissions of the impersonated access key. This affects `PutObjectHandler` (standard and tables/warehouse bucket paths) and `PutObjectPartHandler` (multipart uploads). Users of the open-source `minio/minio` project should upgrade to MinIO AIStor `RELEASE.2026-04-11T03-20-12Z` or later. If upgrading is not immediately possible, block unsigned-trailer requests at the load balancer. Reject any request containing `X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER` at the reverse proxy or WAF layer. Clients can use `STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER` (the signed variant) instead. Alternatively, restrict WRITE permissions. Limit `s3:PutObject` grants to trusted principals. While this reduces the attack surface, it does not eliminate the vulnerability since any user with WRITE permission can exploit it with only their access key.
An authentication bypass vulnerability has been identified in MinIO's object storage system, specifically in the 'STREAMING-UNSIGNED-PAYLOAD-TRAILER' code path. This vulnerability allows any user with a valid access key to write arbitrary objects to any bucket, without needing the secret key or a valid cryptographic signature. The issue affects all MinIO deployments through the last release of the open-source 'minio/minio' project. The vulnerability was introduced in version 'RELEASE.2023-05-18T00-05-36Z' and patched in 'RELEASE.2026-04-11T03-20-12Z'. The vulnerability arises because the 'PutObjectHandler' and 'PutObjectPartHandler' functions call 'newUnsignedV4ChunkedReader' with a signature verification that only checks for the 'Authorization' header. An attacker can exploit this by omitting the 'Authorization' header and using the 'X-Amz-Credential' query parameter instead, bypassing signature verification and gaining unauthorized write access to buckets.
Users should upgrade to MinIO AIStor 'RELEASE.2026-04-11T03-20-12Z' or later. If an immediate upgrade is not possible, block unsigned-trailer requests at the load balancer or reverse proxy level, and restrict WRITE permissions to trusted principals.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/minio/minio/commit/76913a9fd5c6e5c2dbd4e8c7faf56ed9e9e24091 | [email protected] | Patch |
| https://github.com/minio/minio/pull/16484 | [email protected] | Issue Tracking |
| https://github.com/minio/minio/security/advisories/GHSA-hv4r-mvr4-25vw | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| minio minio | >= 2023-05-18t00-05-36z, < 2026-04-11T03-20-12Z |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | New CVE Received | [email protected] |