CVE-2026-50152
Last modified
CVE-2026-50152 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ceph | ceph | >= 19.0.0, < 19.2.6; >= 20.0.0, < 20.2.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-50152?
How severe is CVE-2026-50152?
How do I fix CVE-2026-50152?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-50146Astro is a web framework. Prior to 6.3.3, when a component u…6.1
- CVE-2026-50147Metabase is an open-source business intelligence and embedde…7.6
- CVE-2026-50148Metabase is an open-source business intelligence and embedde…9.1
- CVE-2026-50149Contour is a Kubernetes ingress controller using Envoy proxy…6.5
- CVE-2026-5015A vulnerability was determined in elecV2 elecV2P up to 3.8.3…4.3
- CVE-2026-50151oras-go is a Go library for managing OCI artifacts. Prior to…7.5
- CVE-2026-50157Auth0 Symfony is a Symfony SDK for Auth0 Authentication and …6.5
- CVE-2026-50158yutu is an AI-powered toolkit for managing and growing YouTu…7.7
- CVE-2026-50159Mermaid is a JavaScript tool that uses Markdown-inspired tex…5.3
- CVE-2026-5016A vulnerability was identified in elecV2 elecV2P up to 3.8.3…7.3
- CVE-2026-50160Hoppscotch is an API development ecosystem. In self-hosted d…10
- CVE-2026-50161libre is a generic library for real-time communications with…9.3
Are you affected by CVE-2026-50152?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
