CVE-2025-30156 — Ceph CephX Hardcoded IV Enables Cluster Takeover

CVE & Vulnerabilities · August 30, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly detailed flaw in Ceph, the open-source distributed storage platform, affects versions before 20.2.4 and 19.2.6. The CephX authentication protocol encrypts its tickets using AES-128-CBC with a fixed initialization vector and no integrity check, which lets an attacker who already holds limited access forge credentials and escalate to full cluster-wide control. Ceph administrators running affected versions should prioritize patching given the scope of access this bug can grant.

// source: nvd.nist.gov ↗

Back to Blog