PT-2026-81922 · Ceph · Ceph
CVE-2025-30156
·
Published
2026-08-21
·
Updated
2026-09-02
CVSS v3.1
8.9
High
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Ceph versions prior to 20.2.4
Ceph versions prior to 19.2.6
Description
The CephX authentication protocol encrypts tickets using AES-128-CBC in an unauthenticated mode with a hard-coded initialization vector and no message authentication. This allows an attacker with a low-privilege key who can observe traffic to use the monitor as an encryption oracle, enabling the forging of credentials and gaining cluster-wide access by splicing ciphertext blocks into tickets for privileged entities such as Manager, MDS, and OSD. Additionally, an attacker with CephX permissions can escalate privileges by flipping a single bit in a service ticket to set the
allow all field to true.Recommendations
Update to version 20.2.4 or later.
Update to version 19.2.6 or later.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ceph