CVE-2025-27414Medium▾ SunlitMinIO allows an SFTP authentication bypass due to improperly trusted SSH key
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
A bug in evaluating the trust of the SSH key used in an SFTP connection to MinIO allows authentication bypass and unauthorized data access.
On a MinIO server with SFTP access configured and using LDAP as an external identity provider, MinIO supports SSH key based authentication for SFTP connections when the user has the sshPublicKey attribute set in their LDAP server. The server trusts the client's key only when the public key is the same as the sshPublicKey attribute.
Due to the bug, when the user has no sshPublicKey property in LDAP, the server ends up trusting the key allowing the client to perform any FTP operations allowed by the MinIO access policies associated with the LDAP user (or any of their groups).
The bug was introduced in https://github.com/minio/minio/commit/91e1487de45720753c9e9e4c02b1bd16b7e452fa.
The following requirements must be met to exploit this vulnerability:
sshPublicKey property set.When this bug is successfully exploited, the attacker can perform any FTP operations (i.e. reading, writing, deleting and listing objects) allowed by the access policy associated with the LDAP user account (and their groups).
github.com/minio/minio >= 0.0.0-20240605075113-91e1487de457, < 0.0.0-20250227184332-4c71f1b4ec0fUpgrade to a patched release:
github.com/minio/minio 0.0.0-20250227184332-4c71f1b4ec0fConnected by shared product, vendor, weakness, or advisory.
CVE-2024-24747High· 8.8Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation
CVE-2026-42600Medium· 4.9MinIO vulnerable to Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
CVE-2023-28433High· 8.8Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
CVE-2025-62506High· 8.1MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
CVE-2026-33419CriticalMinIO LDAP login brute-force via user enumeration and missing rate limit
CVE-2026-41145High· 8.2MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads