# CERT-FR flags Ceph Manila RCE flaw

Published: 2026-10-08 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/c281a0f2-509a-51a7-8f78-c9a60aec8592/cert-fr-flags-ceph-manila-rce-flaw

> CERT-FR advises patching a Ceph Manila vulnerability (CVE-2020-27781) that allows remote code execution and privilege escalation.

CERT-FR issued an advisory covering a vulnerability in Ceph's Manila component (shared file system service) that could allow an attacker to achieve remote code execution and privilege escalation. The affected versions are Manila 15.x prior to 15.2.8, 16.x prior to 16.2.0, and all versions prior to 14.2.16. The flaw is tracked as CVE-2020-27781 and documented in Ceph's own security advisory GHSA-32wm-mjvr-8w9f published 7 October 2026.

No evidence of in-the-wild exploitation is mentioned in the bulletin. CERT-FR recommends administrators consult the vendor's security advisory and apply the available patches for affected Ceph/Manila deployments. Organizations running Ceph storage clusters with the Manila shared filesystem service should prioritize upgrading to the fixed versions to mitigate the risk of remote code execution and privilege escalation.

## Mentioned in this report

- Vulnerabilities: CVE-2020-27781

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1280

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c281a0f2-509a-51a7-8f78-c9a60aec8592/cert-fr-flags-ceph-manila-rce-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
