PT-2026-30978 · Rustfs · Rustfs
Thesmartshadow
·
Published
2026-04-07
·
Updated
2026-04-08
·
CVE-2026-39360
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustFS versions prior to alpha.90
Description
RustFS, a distributed object storage system built in Rust, had a missing authorization check in the multipart copy path (
UploadPartCopy) before version alpha.90. This allowed a low-privileged user, lacking read access to objects in a victim bucket, to exfiltrate those objects by copying them into a multipart upload they control and then completing the upload. This compromised tenant isolation in multi-user or multi-tenant deployments.Recommendations
Update to version alpha.90 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustfs