CVE-2026-73284: Rustfs

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and prepare_service_account_auth sets is_owner for the resulting root-parent service account. This issue is fixed in version 1.0.0-beta.11.

Affected products

  • Rustfs Rustfs: before 1.0.0-beta.11 (fixed in 1.0.0-beta.11)

Published 2026-08-12. Last modified 2026-09-09.