216.73.216.233

CVE-2026-45043

· Published 29/05/2026 13:16 · Modified 29/05/2026 15:11

Labels: CVE-2026-45043 2026-05-29CVE-2026-45043CWE-269[email protected]

Essential information

Published
29/05/2026 13:16
Modified
29/05/2026 15:11
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts attacker-controlled parent, claims, accessKey, and secretKey values without enforcing privilege boundaries or sanitization. This enables privilege escalation to full administrative access using a persistent, attacker-defined credential. This vulnerability is fixed in 1.0.0-beta.2.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rustfs / rustfs cpe:2.3:a:rustfs:rustfs:*:*:*:*:*:*:*:*
minio / minio cpe:2.3:a:minio:minio:*:<1.0.0-beta.2:*:*:*:*:*:*

References