PT-2026-82767 · Ceph · Ceph

·

CVE-2026-50152

·

Published

2026-08-21

·

Updated

2026-09-02

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ceph versions prior to 20.2.4 Ceph versions prior to 19.2.6
Description The Monitor subscription handler fails to properly authorize access to the configuration-key store. A CephX user with mon allow r capabilities can read the entire store by sending a crafted MMonSubscribe message. The configuration-key store contains sensitive secrets, such as OSD LUKS disk-encryption passphrases and the SSH private key used by cephadm to access hosts in the cluster. Under default cephadm configurations, this key provides root access to every node, allowing a low-privileged read-only account to achieve full cluster and host compromise.
Recommendations Update to version 20.2.4 or later. Update to version 19.2.6 or later.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CEPH-2026-50152
CVE-2026-50152
ECHO-C8D6-5E39-6E63
GHSA-RG9P-5XCP-WM8H

Affected Products

Ceph