S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-41266 Scanner

CVE-2021-41266 scanner - Authentication Bypass vulnerability in minio console

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-41266
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All users on release v0.12.2 and before are affected and are advised to update to 0.12.3 or newer. Users unable to upgrade should add automountServiceAccountToken: false to the operator-console deployment in Kubernetes so no service account token will get mounted inside the pod, then disable the external identity provider authentication by unset the CONSOLE_IDP_URL, CONSOLE_IDP_CLIENT_ID, CONSOLE_IDP_SECRET and CONSOLE_IDP_CALLBACK environment variable and instead use the Kubernetes service account token.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
consoleby minio
< 0.12.3
Updated Aug 19, 2026View on NVD →
Detail

Minio console is a graphical user interface used for managing the MinIO operator, which is a multi-cloud object storage project. It is deployed on Kubernetes and provides an easy-to-use interface for managing object storage clusters across multiple cloud providers. The console enables users to monitor and manage their object storage infrastructure from a single, centralized location.

CVE-2021-41266 is a critical vulnerability detected in the Minio console version v0.12.2 and earlier. This vulnerability can be exploited to bypass the authentication mechanism of the console when an external identity provider (IDP) is enabled. This means that an attacker can potentially gain unauthorized access to the console and manipulate or steal sensitive data stored in the object storage cluster.

If exploited, the CVE-2021-41266 vulnerability can lead to serious consequences for organizations using Minio console. Attackers can gain access to sensitive data stored in the object storage cluster and manipulate or steal it. An attacker can also carry out attacks such as ransomware, command and control attacks, and data exfiltration.

Thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. With a comprehensive database of the latest vulnerabilities and proactive alerting, s4e.io helps organizations stay ahead of cyber threats and protect their digital assets.

 

REFERENCES

Solution Advice

To protect against this serious vulnerability, users are advised to update their Minio console installation to version v0.12.3 or newer. However, if upgrading is not possible, the following measures can be taken:

  • Add automountServiceAccountToken: false to the operator-console deployment in Kubernetes
  • Disable external IDP authentication by unsetting the CONSOLE_IDP_URL, CONSOLE_IDP_CLIENT_ID, CONSOLE_IDP_SECRET, and CONSOLE_IDP_CALLBACK environment variables
  • Use the Kubernetes service account token instead

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.