Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-50152— Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users

Quick assessment

Affected
ceph ceph
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Ceph 是一个开源的分布式存储平台,提供对象存储、块存储和文件存储。在 20.2.4 和 19.2.6 之前的版本中,Monitor 订阅处理器未能对配置密钥(config-key)存储库的访问进行适当的授权,使得仅具备 权限的任意 CephX 用户通过发送一条特制的 消息即可读取整个配置密钥存储库。该存储库中保存着敏感信息,包括 OSD LUKS 磁盘加密口令;在由 cephadm 管理的集群中,还包含 cephadm 用于访问集群中所有主机的 SSH 私钥。由于在默认 cephadm 配置下,该 SSH 私钥

CVSS 9.1 · Critical EPSS 0.16% · P6

Affected Version Matrix 2

VendorProduct Version RangeStatus
ceph ceph >= 19.0.0, < 19.2.6 affected
>= 20.0.0, < 20.2.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-50152

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Source: CVE Program / CVE List V5
Vulnerability Description
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ceph ceph >= 19.0.0, < 19.2.6 -

II. Public POCs for CVE-2026-50152

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-50152

登录查看更多情报信息。

Patches & Fixes for CVE-2026-50152 (2)

Vendor Advisories for CVE-2026-50152 (1)

Same Patch Batch · ceph · 2026-08-27 · 4 CVEs total

CVE-2025-30156 8.9 HIGH Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential for
CVE-2026-39944 8.8 HIGH Ceph: CephX AES Authentication error
CVE-2026-54330 8.1 HIGH Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr

IV. Related Vulnerabilities

V. Comments for CVE-2026-50152

No comments yet


Leave a comment