Threat Advisory

MinIO Object Storage Vulnerability Enables Unauthorized Privilege Escalation Attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical privilege escalation vulnerability CVE-2025-62506, with a CVSS score of 8.1 has been identified in a high-performance, S3-compatible object storage platform that could allow attackers to bypass session policy restrictions and gain elevated permissions through service or STS accounts. The flaw originated from an issue in the IAM policy validation process, where the system incorrectly relied on a parameter called DenyOnly, allowing restricted accounts to create unrestricted service accounts under the same user. This misconfiguration enabled unauthorized privilege escalation, granting full parent-level access to new accounts and allowing unauthorized reading, modification, or deletion of data across multiple storage buckets. The vulnerability poses a significant confidentiality and integrity risk for cloud and AI/ML workloads using the affected APIs. Exploitation requires only valid credentials for restricted accounts, making it a high-severity yet low-complexity issue. The flaw has been addressed in the latest stable release, and users are urged to update immediately, audit existing service accounts, remove any unauthorized ones, and review access logs for suspicious activity.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical privilege escalation vulnerability CVE-2025-62506, with a CVSS score of 8.1 has been identified in a high-performance, S3-compatible object storage platform that could allow attackers to bypass session policy restrictions and gain elevated permissions through service or STS accounts. The flaw originated from an issue in the IAM policy validation process, where the system incorrectly relied on a parameter called DenyOnly, allowing restricted accounts to create unrestricted service accounts under the same user. This misconfiguration enabled unauthorized privilege escalation, granting full parent-level access to new accounts and allowing unauthorized reading, modification, or deletion of data across multiple storage buckets. The vulnerability poses a significant confidentiality and integrity risk for cloud and AI/ML workloads using the affected APIs. Exploitation requires only valid credentials for restricted accounts, making it a high-severity yet low-complexity issue. The flaw has been addressed in the latest stable release, and users are urged to update immediately, audit existing service accounts, remove any unauthorized ones, and review access logs for suspicious activity.[emaillocker id="1283"]

RECOMMENDATION:

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu