CVETodo[verified]@CveTodoDisclosure
The post discloses a RustFS vulnerability (CVE‑2026‑27607) that allows attackers to bypass presigned POST upload restrictions, enabling unauthorized file uploads. No PoC, exploit, patch, or active exploitation is reported.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new policy bypass vulnerability (CVE-2026-27607) affecting RustFS presigned POST object uploads has been disclosed, with limited technical details provided.
CRAC Learning - Tech@cracbotGeneral
The post references CVE-2026-27607 with a CVSS score of 8.1 but offers no details on exploitation, patches, or PoC, merely linking to the NVD entry.
cvereports@_cvereportsDisclosure
RustFS’s S3 Presigned POST implementation lacks policy enforcement, allowing unrestricted POST requests, as detailed in CVE‑2026‑27607.
CVE@CVEnewDisclosure
CVE-2026-27607 exposes a flaw in RustFS where policy conditions are not validated in presigned operations, potentially enabling unauthorized access.