MinIO AIStor STS AssumeRoleWithLDAPIdentity Endpoint Brute-Force Vulnerability

Vulnerability

A vulnerability exists in MinIO AIStor's Security Token Service (STS) AssumeRoleWithLDAPIdentity endpoint, prior to RELEASE.2026-03-17T21-25-16Z. This vulnerability allows for LDAP credential brute-forcing, enabled by distinguishable error responses that permit username enumeration and a lack of rate limiting on authentication attempts. An unauthenticated network attacker can exploit this to enumerate valid LDAP usernames and perform unlimited password guessing, ultimately obtaining temporary AWS-style STS credentials. This access allows the attacker to interact with the victim's S3 buckets and objects.

Impact

Exploitation of this vulnerability allows an attacker to enumerate valid LDAP usernames and perform high-speed password brute-force attacks against these users. Successful exploitation leads to the acquisition of temporary AWS-style STS credentials, which can be used to access the victim's S3 resources.

Remediation

Users should upgrade to MinIO AIStor RELEASE.2026-03-17T21-25-16Z or later. If an immediate upgrade is not possible, network-level rate limiting can be implemented using a reverse proxy or WAF to restrict requests to the STS AssumeRoleWithLDAPIdentity endpoint. Additionally, firewall restrictions can be applied to limit access to trusted networks or IP ranges. Configuring account lockout policies on the LDAP server can also help, although this may cause denial-of-service for legitimate users.

Added: Mar 24, 2026, 8:21 PM
Updated: Mar 24, 2026, 8:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.