THREATPORT/VULNERABILITY/CVE-2026-42600
MEDIUM SEVERITY

CVE-2026-42600

Minio vulnerability

CVSS
4.9
EPSS
8.5%
EPSS pct
94th
Exploited
No known
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
Affected vendor
Minio
Affected product
Minio
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness type (CWE)
Published
2026-05-11

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring high privileges, no user interaction. Successful exploitation leads to high impact to confidentiality.

Its EPSS score of 8.5% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 94% of all scored CVEs.

Check your external exposure to CVE-2026-42600

  • Confirm whether Minio Minio is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2026-42600.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2026-42600

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2026-42600 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2026-42600?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2026-42600.

Start free scan

No credit card. Agentless.