Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-55949

28
FAUCET Score

CVE-2024-55949 describes a critical privilege escalation vulnerability in MinIO, an S3-compatible object store, specifically within its IAM import API. This flaw impacts all MinIO users running versions from commit 580d9db85e04f1b63cc2909af50f0ed08afa965f up to the fix in RELEASE.2024-12-13T22-19-12Z. Rated with a CVSSv4 score of 9.3 (Critical), the vulnerability is easily exploitable over the network with low attack complexity, allowing an unauthenticated attacker to achieve high confidentiality and integrity impacts. There are no known workarounds, necessitating an immediate upgrade to a patched version. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules or proof-of-concept code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal.

Impacted Technologies

VendorProductVersion(s)CPE
MinioMinio
>= RELEASE.2022-06-25T15-50-16Z, < RELEASE.2024-12-13T22-19-12ZCNA affected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.72%
Probability of exploitation in next 30 days
EPSS Percentile
50.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0072 is in the 33rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/minio/minioFixed in: 0.0.0-20241213221912-68b004a48f41

Vendor Advisories (2)

redhatCVE-2024-55949Important

minio: Privilege escalation in IAM import API in MinIO

Dec 16, 2024
goGHSA-cwq8-g58r-32hghigh

MinIO vulnerable to privilege escalation in IAM import API

Dec 16, 2024

References

github.com / minio/minio/commit/580d9db85e04f1b63cc2909af50f0ed08afa965f
github.com / minio/minio/commit/f246c9053f9603e610d98439799bdd2a6b293427
github.com / minio/minio/pull/20756
github.com / minio/minio/security/advisories/GHSA-cwq8-g58r-32hg