Improper Verification of Cryptographic Signature in Ceph - CVE-2026-39944
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges to full RGW administrative access.
The vulnerability exists due to improper verification of a cryptographic signature in RGW STS session tokens when processing a valid STS token. A remote user can tamper with a token using CBC bit-flipping to escalate privileges to full RGW administrative access.
Exploitation requires STS to be enabled and a single valid STS token already held by the attacker.