PT-2026-2143 · Rustfs · Rustfs

Threonine

·

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2026-22042

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RustFS versions prior to 1.0.0-alpha.79
Description RustFS is a distributed object storage system built in Rust. The ImportIam API endpoint incorrectly validates permissions using ExportIAMAction instead of ImportIAMAction. This allows a principal with only export IAM permissions to perform import operations. Importing IAM data involves privileged write actions, including the creation or modification of users, groups, policies, and service accounts, potentially leading to unauthorized IAM modification and privilege escalation.
Recommendations Update to version 1.0.0-alpha.79 or later.

Exploit

Fix

LPE

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-22042
GHSA-VCWH-PFF9-64CC

Affected Products

Rustfs