← Vulnerability feed

Vulnerability record · CVE-2022-35919 · published 1 August 2022

CVE-2022-35919: MinIO ServerUpdate path traversal exposes arbitrary readable files

Minio · Minio

MinIO contains a path traversal flaw (CWE-22) where an admin user authorized for the admin:ServerUpdate action can trigger an error that returns the content of an arbitrary requested path. Because the MinIO process can read files anywhere the OS account permits, this leaks host files to an authenticated administrator. The issue is fixed in later versions, and the advisory notes a workaround for those who cannot upgrade.

2.7 CVSS 3.1 Low EPSS 52% · top 1.1% CWE-22 · Path traversal
2.7CVSS 3.1 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the content of the path requested. Any normal OS system would allow access to contents at any arbitrary paths that are readable by MinIO process. Users are advised to upgrade. Users unable to upgrade may disable ServerUpdate API by denying the `admin:ServerUpdate` action for your admin users via IAM policies.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

medium priorityExploitation requires an already-privileged admin account and yields read-only disclosure, but public exploit material and a high EPSS score raise the practical risk.

What it is

MinIO contains a path traversal flaw (CWE-22) where an admin user authorized for the admin:ServerUpdate action can trigger an error that returns the content of an arbitrary requested path. Because the MinIO process can read files anywhere the OS account permits, this leaks host files to an authenticated administrator. The issue is fixed in later versions, and the advisory notes a workaround for those who cannot upgrade.

Impact

An attacker with admin:ServerUpdate rights gains read access to any file readable by the MinIO process on the underlying host, potentially exposing configuration, credentials or other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached over the network via the MinIO admin API (AV:N) and requires high privileges, specifically an admin account holding admin:ServerUpdate (PR:H); no user interaction is needed (UI:N).

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.52334, ~98.9th percentile) and the GitHub security advisory is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Upgrade MinIO to a version containing the fix (commit bc72e4226e669d98c8e0f3eccc9297be9251c692 / PR 15429).
  • If upgrading is not possible, deny the admin:ServerUpdate action for admin users via IAM policies to disable the ServerUpdate API.
  • Restrict admin API access to trusted networks and limit the number of accounts holding admin:ServerUpdate.
  • Run the MinIO process under a least-privilege OS account so files outside its data directories are not readable.
  • Review IAM policies for any admin users retaining ServerUpdate rights after remediation.

Detection

  • Monitor MinIO admin API calls invoking ServerUpdate, especially those returning error responses with file content.
  • Alert on admin:ServerUpdate usage by accounts that do not normally perform server updates.
  • Watch for anomalous reads of host files by the MinIO process user (e.g., auditd or EDR file access telemetry).
  • Correlate MinIO audit logs for path-like or traversal sequences in ServerUpdate requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-35919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-28434MinIO metadata bucket name check bypass allows object write to any bucketMinIO before RELEASE.2023-03-20T20-16-18Z fails to properly validate the metadata bucket name when processing PostPolicyBucket, letting crafted reque…KEVEPSS 7.9%analysed7.5CVE-2023-28432MinIO cluster deployment leaks environment variables including root credentialsIn MinIO distributed cluster deployments from RELEASE.2019-12-17T23-16-33Z up to RELEASE.2023-03-20T20-16-18Z, the server returns all environment var…KEVEPSS 84%analysed9.2CVE-2026-33322Minio improper authentication vulnerabilityMinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-16Z, a JWT algorithm confusio…EPSS 0.61%9.1CVE-2026-33419Minio improper restriction of authentication attempts vulnerabilityMinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithL…EPSS 0.54%8.8CVE-2026-40344Minio improper authentication vulnerabilityMinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat…EPSS 0.72%8.8CVE-2026-41145Minio improper authentication vulnerabilityMinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04-11T03-20-12Z, an authenticat…EPSS 0.60%8.8CVE-2024-24747Minio improper privilege management vulnerabilityMinIO is a High Performance Object Storage. When someone creates an access key, it inherits the permissions of the parent key. Not only for `s3:*` ac…EPSS 34%8.8CVE-2023-28433Minio exposure of resource to wrong sphere vulnerabilityMinio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filt…EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2022-35919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.