Description
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6
Published: 2026-08-27
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure & Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Ceph is an open-source distributed storage platform that offers object, block, and file storage. In versions earlier than 20.2.4 and 19.2.6, the Monitor subscription handler does not enforce proper authorization for accessing the configuration‑key store. Any CephX user that has only the "mon allow r" capability can read the entire store by sending a single crafted MMonSubscribe message, exposing sensitive contents. The key store contains operational secrets such as OSD LUKS disk‑encryption passphrases and, on cephadm‑managed clusters, the SSH private key used by cephadm to reach every host. That key effectively provides root access on all nodes; therefore a low‑privilege read‑only account can leverage this flaw to achieve full cluster and host compromise. The vulnerability is mitigated in Ceph 20.2.4 and 19.2.6.

Affected Systems

The vulnerability affects Ceph deployments that use the MON subscription handler, specifically any cluster where CephX users are granted the mon allow r capability. The affected product is the Ceph Monitor component within the Ceph distributed storage system; versions prior to 20.2.4 and 19.2.6 are vulnerable.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal; an attacker must possess or obtain CephX credentials that include mon allow r. Once authenticated, the attacker can send MMonSubscribe requests to an honest monitor and retrieve the full config-key store, leading to high impact. The reliance on privileged capabilities suggests that any compromise of low‑privilege CephX users can be leveraged to reach critical security secrets.

Generated by OpenCVE AI on August 28, 2026 at 06:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ceph update that addresses the MON subscription handler authorization flaw.
  • Revoke or restrict the mon allow r capability for all non‑admin CephX users and re‑apply appropriate role configurations.
  • Enable audit logging for MMonSubscribe requests and regularly review logs for anomalous config‑key access patterns.

Generated by OpenCVE AI on August 28, 2026 at 06:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the MON subscription handler of Ceph, a distributed storage system. The handler does not properly authorize access to the config-key store when processing MMonSubscribe messages. Any CephX user holding mon allow r capabilities can read the entire config-key store, which contains sensitive operational secrets including OSD LUKS disk encryption passphrases and, on clusters managed by cephadm, the SSH private key used to administer every host. Exposure of these secrets can lead to full host-level root access and compromise of encrypted data at rest. Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon allow r` capabilities to read the entire store by sending a single crafted MMonSubscribe message. The config-key store holds sensitive secrets including OSD LUKS disk-encryption passphrases and, on cephadm-managed clusters, the SSH private key that cephadm uses to reach every host in the cluster. Because that key grants root on every node under the default cephadm configuration, a low-privileged read-only account can escalate to full cluster and host compromise. This issue is fixed in versions 20.2.4 and 19.2.6
Title ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}


Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Ceph
Ceph ceph
Vendors & Products Ceph
Ceph ceph

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the MON subscription handler of Ceph, a distributed storage system. The handler does not properly authorize access to the config-key store when processing MMonSubscribe messages. Any CephX user holding mon allow r capabilities can read the entire config-key store, which contains sensitive operational secrets including OSD LUKS disk encryption passphrases and, on clusters managed by cephadm, the SSH private key used to administer every host. Exposure of these secrets can lead to full host-level root access and compromise of encrypted data at rest.
Title ceph: ceph: MON subscription handler exposes config-key store to low-privilege CephX users
Weaknesses CWE-862
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-01T14:48:11.476Z

Reserved: 2026-06-03T20:54:20.431Z

Link: CVE-2026-50152

cve-icon Vulnrichment

Updated: 2026-08-28T15:06:12.054Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-28T00:18:07.073

Modified: 2026-09-08T21:11:56.250

Link: CVE-2026-50152

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-19T17:57:46Z

Links: CVE-2026-50152 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:45:04Z

Weaknesses