Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-24747

55
FAUCET Score

CVE-2024-24747 is a high-severity privilege escalation vulnerability affecting MinIO High Performance Object Storage versions prior to RELEASE.2024-01-31T20-20-33Z. This flaw allows an attacker with legitimate access to create an access key that inherits overly permissive "admin" rights from a parent key, enabling them to bypass intended S3 permissions and escalate privileges. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low privileges, potentially leading to full compromise of confidentiality, integrity, and availability. While not currently listed on the CISA KEV catalog or showing significant community discussion, public exploit code (EDB-51976) is available, indicating a clear path for exploitation. Organizations using affected MinIO versions should prioritize patching to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
2024-01-31t20-20-33zCPE matchmatch criteria
cpe:2.3:a:minio:minio:2024-01-31t20-20-33z:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
34.09%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-51976 · Apr 12, 2024
This CVE's current EPSS score of 0.3409 is in the 97th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/minio/minioFixed in: 0.0.0-20240131185645-0ae4915a9391

Vendor Advisories (1)

goGHSA-xx8w-mq23-29g4high

Minio unsafe default: Access keys inherit `admin` of root user, allowing privilege escalation

Feb 1, 2024

References

github.com / minio/minio/commit/0ae4915a9391ef4b3ec80f5fcdcf24ee6884e776
Patch
github.com / minio/minio/releases/tag/RELEASE.2024-01-31T20-20-33Z
PatchRelease Notes
github.com / minio/minio/security/advisories/GHSA-xx8w-mq23-29g4
ExploitPatchVendor Advisory