CVE-2026-73286: Rustfs

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1.0.0-beta.12.

Affected products

  • Rustfs Rustfs: before 1.0.0-beta.12 (fixed in 1.0.0-beta.12)

Published 2026-08-12. Last modified 2026-09-09.