CVE-2026-50152
highCVSS v3 Base Score
8.2
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Attack Characteristics
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
Low
Availability
Low
Published: August 19, 2026 (18 days ago)
Last Modified: August 19, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in the MON subscription handler of Ceph, a distributed storage system. The handler does not properly authorize access to the config-key store when processing MMonSubscribe messages. Any CephX user holding mon allow r capabilities can read the entire config-key store, which contains sensitive operational secrets including OSD LUKS disk encryption passphrases and, on clusters managed by cephadm, the SSH private key used to administer every host. Exposure of these secrets can lead to full host-level root access and compromise of encrypted data at rest.
CWE
CWE-862Affected Products
Red Hat Ceph Storage 4Red Hat Ceph Storage 5Red Hat Ceph Storage 6Red Hat Ceph Storage 7Red Hat Ceph Storage 8Red Hat Ceph Storage 9