Junglewise Threat Intelligence

CVE-2026-55188: RustFS authorization bypass in ListRemoteTargetHandler replication API

CVE-2026-55188 · Severity: high · CVSS 8.2 · Published 2026-06-26

Technologies: Rustfs.

Executive brief

RustFS, a distributed storage system, contains a security flaw in its administrative interface for managing data replication. An authenticated user without administrative privileges can access sensitive configuration details, including the secret access keys used to connect to remote storage targets. This could allow an unauthorized user to gain full access to data stored on remote backup or replication servers, potentially leading to a significant data breach.

Technical details

An authorization bypass exists in the ListRemoteTargetHandler within the RustFS bucket replication admin API. The handler, located at /rustfs/admin/v3/list-remote-targets, verifies that a request contains valid credentials but fails to perform a secondary authorization check to ensure the caller possesses replication or administrator permissions. An attacker with any valid account can invoke this endpoint to retrieve BucketTarget objects. These objects contain sensitive fields including accessKey, secretKey, and sessionToken for remote replication targets. The vulnerability was introduced in commit 3c7b66e and is resolved in version 1.0.0-beta.9.

Affected products

  • rustfs RustFS 1.0.0-alpha.1 to 1.0.0-beta.8

Timeline

  • 2026-06-11: advisory: GitHub Security Advisory published
  • 2026-06-26: disclosed: NVD publication date
  • 2026-06-26: patched: Fix confirmed in version 1.0.0-beta.9

References