CVE-2026-33419: MinIO: LDAP login brute-force via user enumeration and missing rate limit
Impact What kind of vulnerability is it? Who is impacted?
MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects.
All deployments with LDAP configured running an affected version are impacted.
There are two vulnerabilities:
1. User Enumeration via Distinguishable Error Messages (CWE-204) 2. Missing Rate Limiting on STS Authentication Endpoints (CWE-307)
When exploited together, an attacker can:
1. Enumerate valid LDAP usernames by observing error message differences. 3. Perform high-speed password brute-force attacks against confirmed valid users. 4. Upon finding valid credentials, obtain temporary AWS-style STS credentials (AccessKeyId, SecretAccessKey, SessionToken) with full access to the victim user's S3 resources.
Affected Versions
All MinIO releases through the final release of the minio/minio open-source project.
Patches
Fixed in: MinIO AIStor RELEASE.2026-03-17T21-25-16Z
Binary Downloads
| Platform | Architecture | Download | | -------- | ------------ | --------------------------------------------------------------------------- | | Linux | amd64 | minio | | Linux | arm64 | minio | | macOS | arm64 | minio | | macOS | amd64 | minio | | Windows | amd64 | minio.exe |
FIPS Binaries
| Platform | Architecture | Download | | -------- | ------------ | --------------------------------------------------------------------------- | | Linux | amd64 | minio.fips | | Linux | arm64 | minio.fips |
Package Downloads
| Format | Architecture | Download | | ------ | ------------ | ----------------------------------------------------------------------------------------------------------------------------------- | | DEB | amd64 | minio20260317212516.0.0amd64.deb | | DEB | arm64 | minio20260317212516.0.0arm64.deb | | RPM | amd64 | minio-20260317212516.0.0-1.x8664.rpm | | RPM | arm64 | minio-20260317212516.0.0-1.aarch64.rpm |
Container Images
bash Standard docker pull quay.io/minio/aistor/minio:RELEASE.2026-03-17T21-25-16Z podman pull quay.io/minio/aistor/minio:RELEASE.2026-03-17T21-25-16Z
FIPS docker pull quay.io/minio/aistor/minio:RELEASE.2026-03-17T21-25-16Z.fips podman pull quay.io/minio/aistor/minio:RELEASE.2026-03-17T21-25-16Z.fips
Homebrew (macOS)
bash brew install minio/aistor/minio
Workarounds
- Users of the open-source minio/minio project should upgrade to MinIO AIStor RELEASE.2026-03-17T21-25-16Z or later.
If upgrading is not immediately possible:
- Network-level rate limiting: Use a reverse proxy (e.g., nginx, HAProxy) or WAF to rate-limit requests to the /?Action=AssumeRoleWithLDAPIdentity endpoint. - Firewall restrictions: Restrict access to the STS endpoint to trusted networks/IP ranges only. - LDAP account lockout: Configure account lockout policies on the LDAP server itself (e.g., Active Directory lockout threshold). Note: this protects against brute-force but not enumeration, and may cause denial-of-service for legitimate users.
Other sources
MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33419?
CVE-2026-33419 is considered a high severity vulnerability due to its potential for LDAP credential brute-force attacks.
How do I fix CVE-2026-33419?
To fix CVE-2026-33419, it is recommended to update MinIO to a version beyond the vulnerable release dated March 17, 2026.
What systems are affected by CVE-2026-33419?
CVE-2026-33419 affects MinIO versions up to 2026-03-17 that implement the STS AssumeRoleWithLDAPIdentity endpoint.
What types of attacks are possible with CVE-2026-33419?
CVE-2026-33419 allows attackers to perform brute-force login attempts through user enumeration and is susceptible to account takeover.
Who is at risk due to CVE-2026-33419?
Organizations using vulnerable versions of MinIO that utilize LDAP authentication are at risk due to CVE-2026-33419.