# CERT-FR Flags Multiple Ceph Vulnerabilities

Published: 2026-08-20 · Severity: routine · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/dcbddb38-5d46-54d3-819a-829ba0d47069/cert-fr-flags-multiple-ceph-vulnerabilities

> CERT-FR advisory warns of multiple Ceph vulnerabilities enabling privilege escalation, data confidentiality breaches, and security bypass.

CERT-FR has published an advisory detailing multiple vulnerabilities affecting Ceph, the open-source distributed storage system, impacting versions 20.2.x prior to 20.2.4 and versions prior to 19.2.6. These flaws, tracked as CVE-2025-30156, CVE-2026-39944, CVE-2026-50152, and CVE-2026-54330, could allow an attacker to escalate privileges, compromise data confidentiality, or bypass security policies within affected Ceph deployments.

The advisory references four GitHub Security Advisories published by the Ceph project on August 19, 2026, which contain technical details and remediation guidance. No evidence of active exploitation is mentioned in the advisory; organizations running affected Ceph versions are advised to consult the vendor's security bulletins and apply available patches to mitigate the identified risks.

## Mentioned in this report

- Vulnerabilities: CVE-2025-30156, CVE-2026-39944, CVE-2026-50152, CVE-2026-54330

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1057

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dcbddb38-5d46-54d3-819a-829ba0d47069/cert-fr-flags-multiple-ceph-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
