PT-2026-44474 · Rustfs · Rustfs

·

CVE-2026-47136

·

Published

2026-05-28

·

Updated

2026-05-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RustFS versions prior to 1.0.0-beta.2
Description The console endpoint "GET /rustfs/console/license" returns parsed license metadata, including the license subject and expiration timestamp in JSON format, without requiring authentication. Any client capable of reaching the console listener can query this endpoint without providing credentials.
Recommendations Update to version 1.0.0-beta.2.

Exploit

Fix

Information Disclosure

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47136
GHSA-XP32-GXQ2-3V52

Affected Products

Rustfs