Authorization Bypass in Ceph's Monitor Subscription Handler
CVE-2026-50152
9.1CRITICAL
What is CVE-2026-50152?
Ceph, an open-source distributed storage platform, has a vulnerability in its Monitor subscription handler that allows unauthorized access to sensitive configuration keys. Specifically, users with mon allow r capabilities can read the entirety of the configuration-key store by sending a specially crafted MMonSubscribe message. This malicious access could lead to exposure of critical secrets, such as OSD LUKS disk-encryption passphrases and cephadm-managed cluster SSH private keys. The breach opens up risks for full cluster and host compromise, making it crucial for users to upgrade to versions 20.2.4 or 19.2.6, where the issue has been addressed.
Affected Version(s)
ceph >= 19.0.0, < 19.2.6 < 19.0.0, 19.2.6
ceph >= 20.0.0, < 20.2.4 < 20.0.0, 20.2.4
