CVE-2021-41266 is a critical authentication bypass vulnerability affecting Minio console versions v0.12.2 and earlier, specifically when an external Identity Provider (IDP) is enabled. This flaw allows unauthenticated attackers to gain full control over the Minio console, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed on the CISA KEV catalog, public Nuclei templates exist for detecting this vulnerability, indicating potential for exploitation, though there is no evidence of active exploitation or significant community discussion. Organizations are strongly advised to update to Minio console v0.12.3 or newer, or implement the provided mitigation steps if immediate upgrade is not feasible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.3CPE matchmatch criteria | cpe:2.3:a:min:minio_console:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.