← Back to CVE List
Vulnerability Intelligence Report
Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users

CVE-2026-50152

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.2
Impact Score:5.3
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-285 ↗CWE-285: Improper Authorization

Affected Products & Versions

Vendor Product Affected Versions
ceph ceph >= 19.0.0, < 19.2.6 (affected), >= 20.0.0, < 20.2.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.162%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-06-03T20:54:20
Published2026-08-27T20:53:42
Last Updated2026-09-01T14:48:11

LINK COPIED TO CLIPBOARD