Privilege Escalation Vulnerability in RustFS Distributed Object Storage System
CVE-2026-22043
5.7MEDIUM
What is CVE-2026-22043?
A flaw in the deny_only short-circuit within the RustFS IAM allows unauthorized service accounts to generate unrestricted accounts with full privileges. This vulnerability enables attackers to escalate their privileges and bypass session and inline policy restrictions, posing a significant security risk to systems utilizing RustFS versions 1.0.0-alpha.13 through 1.0.0-alpha.78. The issue has been rectified in version 1.0.0-alpha.79.
Affected Version(s)
rustfs >= 1.0.0-alpha.13, < 1.0.0-alpha.79
