Improper Header Validation in MinIO Affects Object Storage Functionality
CVE-2026-97731
What is CVE-2026-97731?
MinIO, up to version 7aac2a2, is susceptible to an improper verification of x-amz-* headers, allowing potential attackers to exploit unsigned headers. This limitation permits an individual with a presigned PUT URL to initiate server-side copies of arbitrary objects without sufficient authorization. The exploitation could grant access to objects that the signing key is authorized to read, effectively broadening scope for unauthorized data access and posing significant security risks to users relying on MinIO for their object storage needs. It's essential for administrators of MinIO and affected products to review their security configurations and apply necessary updates to mitigate this risk.
Affected Version(s)
MinIO 0 <= 7aac2a2c5b7c882e68c1ce017d8256be2feea27f
