CVE-2024-55949High· 8.1▾ TwilightA flaw was found in MinIO. Due to insufficient permissions checking in the IAM import API, a user may be able to change their policy mapping to escalate their privileges via a specially crafted configuration file.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
Last analysed / modified upstream
0.7%
— → 8.1
A flaw was found in MinIO. Due to insufficient permissions checking in the IAM import API, a user may be able to change their policy mapping to escalate their privileges via a specially crafted configuration file.
minio: Privilege escalation in IAM import API in MinIO — rated Important by Red Hat. Released 2024-12-16, updated 2026-10-09.
Not affected:
Refer to the advisory for fix availability.
Affected packages:
github.com/minio/minio >= 0.0.0-20220623162515-580d9db85e04, < 0.0.0-20241213221912-68b004a48f41Patched in:
github.com/minio/minio 0.0.0-20241213221912-68b004a48f41Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1442Medium· 6.0grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)
CVE-2024-24747High· 8.8Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
CVE-2026-42600Medium· 4.9MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
CVE-2025-27414MediumMinIO allows an SFTP authentication bypass due to improperly trusted SSH key
CVE-2023-28433High· 8.8Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
CVE-2025-62506High· 8.1MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS