{"id":"BIT-minio-2026-41145","summary":"MinIO has an Unauthenticated Object Write via Query-String Credential Signature Bypass in Unsigned-Trailer Uploads","details":"MinIO is a high-performance object storage system. Starting in 2023.05.18 and prior to 2026.04.11, an authentication bypass vulnerability in MinIO's `STREAMING-UNSIGNED-PAYLOAD-TRAILER` code path\nallows any user who knows a valid access key to write arbitrary objects to any bucket without knowing the secret key or providing a valid cryptographic signature. Any MinIO deployment is impacted. The attack requires only a valid access key (the well-known default `minioadmin`, or any key with WRITE permission on a bucket) and a target bucket name. `PutObjectHandler` and `PutObjectPartHandler` call `newUnsignedV4ChunkedReader` with a signature verification gate based solely on the presence of the `Authorization` header. Meanwhile, `isPutActionAllowed` extracts credentials from either the `Authorization` header or the\n`X-Amz-Credential` query parameter, and trusts whichever it finds. An attacker omits the `Authorization` header and supplies credentials exclusively via the query string. The signature gate evaluates to `false`, `doesSignatureMatch` is never called, and the request proceeds with the permissions of the impersonated access key. This affects `PutObjectHandler` (standard and tables/warehouse bucket paths) and `PutObjectPartHandler` (multipart uploads). Users of the open-source `minio/minio` project should upgrade to MinIO AIStor `2026.04.11` or later. If upgrading is not immediately possible, block unsigned-trailer requests at the load balancer. Reject any request containing `X-Amz-Content-Sha256: STREAMING-UNSIGNED-PAYLOAD-TRAILER` at the reverse proxy or WAF layer. Clients can use `STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER` (the signed variant) instead. Alternatively, restrict WRITE permissions. Limit `s3:PutObject` grants to trusted principals. While this reduces the attack surface, it does not eliminate the vulnerability since any user with WRITE permission can exploit it with only their access key.","aliases":["CVE-2026-41145","GHSA-hv4r-mvr4-25vw","GO-2026-5437"],"modified":"2026-09-08T08:47:42.361217560Z","published":"2026-04-24T16:03:40.498Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:minio:minio:*:*:*:*:*:*:*:*","cpe:2.3:a:minio:minio:*:*:*:*:*:go:*:*"]},"references":[{"type":"FIX","url":"https://github.com/minio/minio/commit/76913a9fd5c6e5c2dbd4e8c7faf56ed9e9e24091"},{"type":"REPORT","url":"https://github.com/minio/minio/pull/16484"},{"type":"ADVISORY","url":"https://github.com/minio/minio/security/advisories/GHSA-hv4r-mvr4-25vw"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41145"}],"affected":[{"package":{"name":"minio","ecosystem":"Bitnami","purl":"pkg:bitnami/minio"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2023.05.18"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/minio/BIT-minio-2026-41145.json"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}],"schema_version":"1.9.0"}