๐Ÿ” CVE Alert

CVE-2026-50152

CRITICAL 9.1

Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only ย `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

CWE CWE-285
Vendor ceph
Product ceph
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for ceph ceph

Be the first to know when new critical vulnerabilities affecting ceph ceph are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low

Affected Versions

ceph / ceph
>= 19.0.0, < 19.2.6 >= 20.0.0, < 20.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h github.com: https://github.com/ceph/ceph/commit/d971bb2b6199f70b1708a20a63fa944ee7a94727 github.com: https://github.com/ceph/ceph/commit/f2840d2fd338ab5de2865f0f78684bbf7b888c84