CVE Database
/

CVE-2026-33322

Back to search

CVE-2026-33322

Published: Mar 24, 2026

Modified: Mar 25, 2026

PUBLISHED

Description

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

VendorProductVersions

minio

minio

affected
>= RELEASE.2022-11-08T05-27-07Z, < RELEASE.2026-03-17T21-25-16Z

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now