AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73286

HIGH · CVSS 8.1 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

RustFS versions prior to 1.0.0-beta.12 are vulnerable to an issue where attacker-controlled request headers can be manipulated to influence identity-based policy conditions, potentially allowing unauthorized access to sensitive resources. This vulnerability poses a high risk, as it can be exploited by authenticated users to bypass security measures. Organizations using RustFS should prioritize upgrading to the latest version to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73286
Severity
HIGH
CVSS
8.1
EPSS
0.24%

Original NVD Description

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap: condition keys, allowing authenticated callers to satisfy identity-based policy conditions. This issue is fixed in version 1.0.0-beta.12.