vulnerability

FreeBSD: VID-511f5aac-ab46-11f0-9446-f02f7497ecda (CVE-2025-62506): minio -- Privilege Escalation via Session Policy Bypass in Service Accounts and STS

Severity
8
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:N)
Published
Oct 17, 2025
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

mino reports: A privilege escalation vulnerability allows service accounts and STS (Security Token Service) accounts with restricted session policies to bypass their inline policy restrictions when performing "own" account operations, specifically when creating new service accounts for the same user.

Solution

freebsd-upgrade-package-minio
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.