CVE-2026-50152: Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users

Published Aug 27, 2026
·
Updated

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  mon allow r capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

Affected Software

1 affected component
ceph Ceph Monitor subscription handler<20.2.4, <19.2.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 20.2.4
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.2.6

Event History

Aug 27, 2026
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which Ceph deployments face the greatest impact?

Cephadm-managed clusters are especially exposed because the config-key store may contain the cephadm SSH private key. Under the default cephadm configuration, that key grants root access to every cluster host.

2

What access does an attacker need to exploit this issue?

An attacker needs valid CephX credentials for any user granted only `mon allow r` capabilities. They can send a single crafted MMonSubscribe message to read the entire configuration-key store; no additional privileges or user interaction are required.

3

Are read-only CephX users sufficient to compromise a cluster?

Yes. A read-only user can retrieve sensitive config-key entries, including OSD LUKS disk-encryption passphrases and potentially the cephadm SSH private key. In default cephadm deployments, obtaining that SSH key can lead to root access across all cluster nodes.

4

Which versions contain the fix?

The issue is fixed in Ceph versions 20.2.4 and 19.2.6. Versions earlier than those releases are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203