Multiples vulnérabilités dans Ceph (20 août 2026)
Multiple vulnerabilities have been discovered in Ceph, allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect older versions of the distributed storage system, requiring immediate patching to mitigate the risk.
Multiple vulnerabilities have been identified within the Ceph distributed storage system. These flaws enable an attacker to gain elevated privileges, potentially leading to full system compromise. Furthermore, attackers can circumvent existing security policies, increasing the attack surface. The vulnerabilities are present in Ceph versions prior to 20.2.4 and 19.2.6. Several CVEs have been assigned to these issues, including CVE-2025-30156, CVE-2026-39944, CVE-2026-50152 and CVE-2026-54330. The CERT-FR has published security advisories detailing these vulnerabilities and recommended remediation steps. Users are advised to consult the linked security advisories for specific instructions on applying the necessary patches and mitigating the risks.