Executive brief
RustFS, a distributed storage system, contains a security flaw in its administrative identity management component. An attacker with limited permissions can bypass security boundaries to create new service accounts with full administrative 'root' privileges. This allows a low-privileged user to gain total control over the storage system, including the ability to access all customer data, modify security settings, and create permanent backdoors.
Technical details
A privilege escalation vulnerability exists in the RustFS `import-iam` endpoint due to improper validation of service account definitions provided in ZIP-supplied JSON payloads. The `ImportIam` handler in `rustfs/src/admin/handlers/user.rs` fails to validate the `parent` field, allowing an attacker to associate new service accounts with the root user (`minioadmin`). Additionally, the endpoint does not sanitize `claims` or enforce privilege boundaries on `accessKey` and `secretKey` values. An attacker with `ImportIAMAction` privileges can exploit this to provision persistent credentials with `consoleAdmin` policies, effectively gaining full administrative control. This bypasses the security checks present in the standard `AddServiceAccount` flow. The issue is resolved in version 1.0.0-beta.2.
Affected products
- RustFS RustFS < 1.0.0-beta.2
Timeline
- 2026-05-09: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE published to NVD