Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/minio/minio
  4. ›
  5. CVE-2025-62506

CVE-2025-62506: MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS

October 16, 2025 (updated October 24, 2025)

A privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing “own” account operations, specifically when creating new service accounts for the same user.

References

  • github.com/advisories/GHSA-jjjj-jwhf-8rgr
  • github.com/minio/minio
  • github.com/minio/minio/commit/c1a49490c78e9c3ebcad86ba0662319138ace190
  • github.com/minio/minio/discussions/21655
  • github.com/minio/minio/issues/21647
  • github.com/minio/minio/pull/21642
  • github.com/minio/minio/security/advisories/GHSA-jjjj-jwhf-8rgr
  • news.ycombinator.com/item?id=45684035
  • nvd.nist.gov/vuln/detail/CVE-2025-62506

Code Behaviors & Features

Detect and mitigate CVE-2025-62506 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20251015170045-c1a49490c78e

Fixed versions

  • 0.0.0-20251015170045-c1a49490c78e

Solution

Upgrade to version 0.0.0-20251015170045-c1a49490c78e or above.

Impact 8.1 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/github.com/minio/minio/CVE-2025-62506.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Nov 2025 00:20:24 +0000.