CVE-2026-33322 is a critical JWT algorithm confusion vulnerability affecting MinIO object storage systems, specifically versions from RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z. An attacker possessing the OpenID Connect ClientSecret can exploit this flaw to forge arbitrary identity tokens. This allows them to obtain S3 credentials with any policy, including full administrative access (consoleAdmin). Rated 9.2 CRITICAL (CVSSv4), this vulnerability has a network attack vector, low complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2022-11-08t05-27-07z, < 2026-03-17t21-25-16zCPE matchmatch criteria | cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.