Vulnerability Description
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Minio | Minio | >= 2022-07-24t01-54-52z, < 2026-04-14t21-32-45z |
Related Weaknesses (CWE)
References
- https://github.com/minio/minio/security/advisories/GHSA-xh8f-g2qw-gcm7MitigationPatchVendor Advisory
FAQ
What is CVE-2026-42600?
CVE-2026-42600 is a vulnerability with a CVSS score of 4.9 (MEDIUM). MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-RE...
How severe is CVE-2026-42600?
CVE-2026-42600 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42600?
Check the references section above for vendor advisories and patch information. Affected products include: Minio Minio.