9.1
CVE-2026-50152
- EPSS 0.16%
- Veröffentlicht 27.08.2026 20:53:42
- Zuletzt bearbeitet 08.09.2026 21:11:56
- Erkennungen
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerceph
≫
Produkt
ceph
Version
>= 19.0.0, < 19.2.6
Status
affected
Version
>= 20.0.0, < 20.2.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.057 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.1 | 3.1 | 5.3 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h
https://github.com/ceph/ceph/commit/d971bb2b6199f70b1708a20a63fa944ee7a94727
https://github.com/ceph/ceph/commit/f2840d2fd338ab5de2865f0f78684bbf7b888c84