Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-39944— Ceph: CephX AES Authentication error

Quick assessment

Affected
ceph ceph
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ceph 是一个开源的分布式存储平台,提供对象存储、块存储和文件存储。在 20.2.4 和 19.2.6 之前的版本中,RADOS 网关(RGW)使用 AES-128-CBC 处理器保护 STS 会话令牌,但该处理器不提供消息认证,这使得持有任一有效 STS 令牌的攻击者可以在未被检测到的情况下篡改令牌,并提升权限至完整的 RGW 管理访问权限。由于密文未经过认证,攻击者可以对令牌中的 、 和 字段执行 CBC 位翻转(bit-flip);若伪造的 值为真,将触发全局管理权限覆盖,从而绕过所有能力(capabili

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-39944

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ceph: CephX AES Authentication error
Source: CVE Program / CVE List V5
Vulnerability Description
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper with it undetected and escalate to full RGW administrative access. Because the ciphertext is unauthenticated, the attacker can perform a CBC bit-flip on the acct_type, perm_type, and is_admin fields of their own token, and a forged is_admin value triggers a global administrative override that bypasses all capability checks. The attack is reachable remotely over the RGW S3 endpoint and is a self-contained modification of a token the attacker already possesses, requiring no encryption oracle and no network observation. It requires only a single valid STS token, which need not carry any elevated privileges, with STS enabled. This issue is fixed in versions 20.2.4 and 19.2.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用已被攻破或存在风险的密码学算法
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ceph ceph >= 19.0.0, < 19.2.6 -

II. Public POCs for CVE-2026-39944

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-39944

登录查看更多情报信息。

Vendor Advisories for CVE-2026-39944 (1)

Vendor Pages for CVE-2026-39944 (2)

Same Patch Batch · ceph · 2026-08-27 · 4 CVEs total

CVE-2026-50152 9.1 CRITICAL Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing c
CVE-2025-30156 8.9 HIGH Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential for
CVE-2026-54330 8.1 HIGH Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr

IV. Related Vulnerabilities

V. Comments for CVE-2026-39944

No comments yet


Leave a comment