๐Ÿ” CVE Alert

CVE-2026-33322

UNKNOWN 0.0

MinIO: JWT Algorithm Confusion in OIDC Authentication

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
4th

MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's OpenID Connect authentication allows an attacker who knows the OIDC ClientSecret to forge arbitrary identity tokens and obtain S3 credentials with any policy, including consoleAdmin. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.

CWE CWE-287
Vendor minio
Product minio
Published Mar 24, 2026
Last Updated Mar 25, 2026
Stay Ahead of the Next One

Get instant alerts for minio minio

Be the first to know when new unknown vulnerabilities affecting minio minio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

minio / minio
>= RELEASE.2022-11-08T05-27-07Z, < RELEASE.2026-03-17T21-25-16Z

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/minio/minio/security/advisories/GHSA-5cx5-wh4m-82fh