---
id: CVE-2024-55949
title: 'minio: Privilege escalation in IAM import API in MinIO (CVE-2024-55949)'
summary: >-
  A flaw was found in MinIO. Due to insufficient permissions checking in the IAM
  import API, a user may be able to change their policy mapping to escalate
  their privileges via a specially crafted configuration file.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-269
vendor: Red Hat
product: github.com/minio/minio
affected:
  - >-
    github.com/minio/minio >= 0.0.0-20220623162515-580d9db85e04, <
    0.0.0-20241213221912-68b004a48f41
patched:
  - github.com/minio/minio 0.0.0-20241213221912-68b004a48f41
published: '2024-12-16'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T03:09:09+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-55949.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-55949.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-55949'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2332681'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-55949'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-55949'
  - url: >-
      https://github.com/minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f
  - url: >-
      https://github.com/minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427
  - url: 'https://github.com/minio/minio/pull/20756'
  - url: 'https://github.com/minio/minio/security/advisories/GHSA-cwq8-g58r-32hg'
  - url: 'https://github.com/minio/minio'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00711
epssPercentile: 0.52118
aliases:
  - GHSA-cwq8-g58r-32hg
  - GO-2024-3336
ecosystem: go
ingestedAt: '2026-10-09T07:36:09.695Z'
---

## Overview

A flaw was found in MinIO. Due to insufficient permissions checking in the IAM import API, a user may be able to change their policy mapping to escalate their privileges via a specially crafted configuration file.

## Vendor advisories

- **Red Hat VEX** · Important · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-55949.json)

**minio: Privilege escalation in IAM import API in MinIO** — rated Important by Red Hat. Released 2024-12-16, updated 2026-10-09.

Not affected:

- Logging Subsystem for Red Hat OpenShift
- OpenShift API for Data Protection
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Data Science (RHODS)
- Red Hat Quay 3

## Remediation

Refer to the advisory for fix availability.

## Package advisory (CVE-2024-55949)

Affected packages:

- `github.com/minio/minio >= 0.0.0-20220623162515-580d9db85e04, < 0.0.0-20241213221912-68b004a48f41`

Patched in:

- `github.com/minio/minio 0.0.0-20241213221912-68b004a48f41`

Source: https://osv.dev/vulnerability/GHSA-cwq8-g58r-32hg
