Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Minio

First CVE: Jun 26, 2018Active for: 8 yearsTotal CVEs: 24
74.0
VTI Score
TOP TARGET

Minio is an open-source object-storage platform widely deployed in containerized and cloud-native environments, where its S3-compatible API and access-control surface make it a target for privilege-escalation and authentication-bypass attacks. The vendor's vulnerability profile concentrates on its core storage server and web console products and exhibits a moderate tendency toward confirmed in-the-wild exploitation, coupled with an elevated propensity for public exploit code availability. Recurring weakness classes include improper privilege management, authentication and authorization flaws, and exposure of sensitive information, reflecting the complexity of managing identity, permissions, and credential handling in a distributed storage system. Defenders should prioritize network isolation and credential management for internet-exposed Minio instances and track updates closely; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
8.3%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Minio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
May 11, 2026
74 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-28432HIGH
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all env
Mar 22, 20237.597YESYES
CVE-2023-28434HIGH
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an obje
Mar 22, 20238.871YESNO
CVE-2024-24747HIGH
MinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` actions, but also `admin:*` actio
Jan 31, 20248.855NOYES
CVE-2022-35919LOW
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can sel
Aug 1, 20222.750NOYES
CVE-2021-21287HIGH
MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerabi
Feb 1, 20217.748NOYES
CVE-2021-43858HIGH
MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for upda
Dec 27, 20218.845NONO
CVE-2026-33322CRITICAL
MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusion vulnerability in MinIO's Open
Mar 24, 20269.831NONO
CVE-2026-40344HIGH
MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authentication bypass vulnerability in Min
Apr 22, 20268.227NONO
CVE-2023-25812HIGH
Minio is a Multi-Cloud Object Storage framework. Affected versions do not correctly honor a `Deny` policy on ByPassGoverance. Ideally, minio should return "Access Denied" to all us
Feb 21, 20238.827NONO
CVE-2021-41137HIGH
Minio is a Kubernetes native application for cloud storage. All users on release `RELEASE.2021-10-10T16-53-30Z` are affected by a vulnerability that involves bypassing policy restr
Oct 13, 20218.827NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
25%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None24 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (45.8%)
High3 (12.5%)
None10 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
2 CVEs
8.3% of CVEs· 100th percentile
Metasploit
1 CVE
4.2% of CVEs· 98th percentile
Nuclei
2 CVEs
8.3% of CVEs· 96th percentile
ExploitDB
2 CVEs
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Minio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Minio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Minio's Products

View all 2 CNAs →

Top CWEs