8.8

CVE-2026-22042

Exploit

RustFS has IAM Incorrect Authorization in ImportIam that Allows Privilege Escalation

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.79, he `ImportIam` admin API validates permissions using `ExportIAMAction` instead of `ImportIAMAction`, allowing a principal with export-only IAM permissions to perform import operations. Since importing IAM data performs privileged write actions (creating/updating users, groups, policies, and service accounts), this can lead to unauthorized IAM modification and privilege escalation. Version 1.0.0-alpha.79 fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rustfs ≫ Rustfs Version 1.0.0 Update alpha1 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha10 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha11 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha12 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha13 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha14 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha15 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha16 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha17 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha18 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha19 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha2 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha20 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha21 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha22 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha23 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha24 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha25 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha26 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha27 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha28 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha29 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha3 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha30 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha31 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha32 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha33 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha34 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha35 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha36 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha37 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha38 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha39 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha4 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha40 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha41 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha42 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha43 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha44 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha45 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha46 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha47 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha48 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha49 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha5 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha50 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha51 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha52 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha53 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha54 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha55 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha56 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha57 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha58 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha59 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha6 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha60 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha61 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha62 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha63 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha64 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha65 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha66 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha67 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha68 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha69 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha7 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha70 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha71 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha72 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha73 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha74 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha75 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha76 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha77 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha78 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha8 SwPlatform rust
Rustfs ≫ Rustfs Version 1.0.0 Update alpha9 SwPlatform rust
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 5.7 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://github.com/rustfs/rustfs/security/advisories/GHSA-vcwh-pff9-64cc
Vendor Advisory
Exploit