Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-50152

Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Back to all
CVE

CVE-2026-50152

Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  mon allow r capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.1
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50152.json, https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h, https://nvd.nist.gov/vuln/detail/CVE-2026-50152, https://github.com/ceph/ceph/commit/d971bb2b6199f70b1708a20a63fa944ee7a94727, https://github.com/ceph/ceph/commit/f2840d2fd338ab5de2865f0f78684bbf7b888c84

Severity

9.1

CVSS Score
0
10

Basic Information

Base CVSS
9.1
EPSS Probability
0.00248%
EPSS Percentile
0.14431%
Introduced Version
048fc68c517f50b9978457f478ca4638f01caa09,0
Fix Available
f2840d2fd338ab5de2865f0f78684bbf7b888c84

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading