Junglewise Threat Intelligence

CVE-2026-45042: RustFS improper authorization in UploadPartCopy operation

CVE-2026-45042 · Severity: info · CVSS 7.1 · Published 2026-05-28

Technologies: Rustfs.

Executive brief

RustFS is a distributed storage system used to manage large amounts of data in 'buckets.' A security flaw in the file-copying feature allows users with basic access to move data between buckets even when security policies should prevent it. This could allow an attacker to bypass data isolation rules and copy sensitive information into a location they fully control, leading to unauthorized data exposure.

Technical details

An authorization bypass exists in the `UploadPartCopy` operation of RustFS due to insufficient validation of cross-bucket policy constraints. While the system independently verifies `GetObject` permissions for the source and `PutObject` permissions for the destination, it fails to enforce bucket-level isolation policies that restrict which sources a destination bucket may accept data from. An attacker with low-privileged network access (valid credentials for both a source and destination bucket) can exploit this to move sensitive data into an attacker-controlled bucket, bypassing tenant isolation. The issue is rooted in `rustfs/src/storage/access.rs` where source and destination checks are decoupled. This vulnerability is resolved in version 1.0.0-beta.2.

Affected products

  • rustfs RustFS < 1.0.0-beta.2

Timeline

  • 2026-05-09: advisory: GitHub advisory published
  • 2026-05-28: disclosed: NVD publication date
  • 2026-05-28: patched: Fixed in version 1.0.0-beta.2

References