PT-2026-81922 · Ceph · Ceph

CVE-2025-30156

·

Published

2026-08-21

·

Updated

2026-09-02

CVSS v3.1

8.9

High

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Ceph versions prior to 20.2.4 Ceph versions prior to 19.2.6
Description The CephX authentication protocol encrypts tickets using AES-128-CBC in an unauthenticated mode with a hard-coded initialization vector and no message authentication. This allows an attacker with a low-privilege key who can observe traffic to use the monitor as an encryption oracle, enabling the forging of credentials and gaining cluster-wide access by splicing ciphertext blocks into tickets for privileged entities such as Manager, MDS, and OSD. Additionally, an attacker with CephX permissions can escalate privileges by flipping a single bit in a service ticket to set the allow all field to true.
Recommendations Update to version 20.2.4 or later. Update to version 19.2.6 or later.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98039
BIT-CEPH-2025-30156
CVE-2025-30156
ECHO-5896-CC77-AA09
GHSA-7Q3Q-3975-QW3Q

Affected Products

Ceph