Improper Header Validation in MinIO Affects Object Storage Functionality
CVE-2026-97731

7.1HIGH

Key Information:

Vendor

Minio

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-97731?

MinIO, up to version 7aac2a2, is susceptible to an improper verification of x-amz-* headers, allowing potential attackers to exploit unsigned headers. This limitation permits an individual with a presigned PUT URL to initiate server-side copies of arbitrary objects without sufficient authorization. The exploitation could grant access to objects that the signing key is authorized to read, effectively broadening scope for unauthorized data access and posing significant security risks to users relying on MinIO for their object storage needs. It's essential for administrators of MinIO and affected products to review their security configurations and apply necessary updates to mitigate this risk.

Affected Version(s)

MinIO 0 <= 7aac2a2c5b7c882e68c1ce017d8256be2feea27f

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.