Rustfs · Rustfs · CVE-2026-47136
**Name of the Vulnerable Software and Affected Versions**
RustFS versions prior to 1.0.0-beta.2
**Description**
The console endpoint "GET /rustfs/console/license" returns parsed license metadata, including the license subject and expiration timestamp in JSON format, without requiring authentication. Any client capable of reaching the console listener can query this endpoint without providing credentials.
**Recommendations**
Update to version 1.0.0-beta.2.