Minio is an open-source object-storage platform widely deployed in containerized and cloud-native environments, where its S3-compatible API and access-control surface make it a target for privilege-escalation and authentication-bypass attacks. The vendor's vulnerability profile concentrates on its core storage server and web console products and exhibits a moderate tendency toward confirmed in-the-wild exploitation, coupled with an elevated propensity for public exploit code availability. Recurring weakness classes include improper privilege management, authentication and authorization flaws, and exposure of sensitive information, reflecting the complexity of managing identity, permissions, and credential handling in a distributed storage system. Defenders should prioritize network isolation and credential management for internet-exposed Minio instances and track updates closely; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minio over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28432HIGH Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all env | Mar 22, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-28434HIGH Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an obje | Mar 22, 2023 | 8.8 | 71 | YES | NO |
CVE-2024-24747HIGH MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actio | Jan 31, 2024 | 8.8 | 55 | NO | YES |
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can sel | Aug 1, 2022 | 2.7 | 50 | NO | YES |
CVE-2021-21287HIGH MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerabi | Feb 1, 2021 | 7.7 | 48 | NO | YES |
CVE-2021-43858HIGH MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for upda | Dec 27, 2021 | 8.8 | 45 | NO | NO |
CVE-2026-33322CRITICAL MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's Open | Mar 24, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-40344HIGH MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in Min | Apr 22, 2026 | 8.2 | 27 | NO | NO |
CVE-2023-25812HIGH Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all us | Feb 21, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-41137HIGH Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restr | Oct 13, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minio.
Media articles that mention a CVE ID that affects a product developed by Minio — matched by CVE ID, not by vendor name.