OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97731

HIGH · CVSS 7.1 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

MinIO versions up to 7aac2a2 are vulnerable due to improper verification of x-amz-* headers, allowing an attacker with a presigned PUT URL to perform unauthorized server-side copy operations on any object accessible by the signing key. This flaw can lead to significant data exposure, as it allows a write permission on one object to escalate to read access across all buckets the key can access. Organizations using affected versions of MinIO should prioritize patching to mitigate the risk of unauthorized data access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97731
Severity
HIGH
CVSS
7.1
EPSS
0.15%
GitHub

Original NVD Description

MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api-router.go dispatches CopyObject on the presence of x-amz-copy-source alone, the holder of a presigned PUT URL scoped to a single object can add that header to the unmodified URL and cause a server-side copy, executed as the signer, of any object the signing key can read. A grant to write one object becomes a read of every bucket that key can reach. Amazon S3 rejects the equivalent request with HTTP 403 AccessDenied. The minio/minio GitHub repository was archived in April 2026; pgsty/silo before 1233254 is also affected.