CVE-2026-27607Disclosure(rustfs / rustfs)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigned POST uploads (PostObject), allowing attackers to bypass content-length-range, starts-with, and Content-Type constraints. This enables unauthorized file uploads exceeding size limits, uploads to arbitrary object keys, and content-type spoofing, potentially leading to storage exhaustion, unauthorized data access, and security bypasses. Version 1.0.0-alpha.83 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rustfs

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
rustfs

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-25: 3Mentions · 2026-02-26: 1Mentions · 2026-03-02: 1Technical Details · 2026-02-25: 3Technical Details · 2026-02-26: 1Technical Details · 2026-03-02: 102-2502-2603-02
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-02-261
Disclosure1
2026-03-021
General1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27607 Policy Bypass Vulnerability in RustFS Presigned POST Object Uploads https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27607

    Post summary

    A new policy bypass vulnerability (CVE-2026-27607) affecting RustFS presigned POST object uploads has been disclosed, with limited technical details provided.

    0000144
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27607 (CVSS:8.1, HIGH) is Analyzed. RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS d..https://nvd.nist.gov/vuln/detail/CVE-2026-27607 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27607 with a CVSS score of 8.1 but offers no details on exploitation, patches, or PoC, merely linking to the NVD entry.

    0000045
    173 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27607: RustFS: The 'Anything Goes' S3 POST Policy RustFS, a distributed object storage system, implemented the S3 Presigned POST protocol but forgot the most important part: enforcing the rules. While it verified the cryptographic signature o... https://cvereports.com/reports/CVE-2026-27607

    Post summary

    RustFS’s S3 Presigned POST implementation lacks policy enforcement, allowing unrestricted POST requests, as detailed in CVE‑2026‑27607.

    0000052
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27607 RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS does not validate policy conditions in presigne… https://www.cve.org/CVERecord?id=CVE-2026-27607

    Post summary

    CVE-2026-27607 exposes a flaw in RustFS where policy conditions are not validated in presigned operations, potentially enabling unauthorized access.

    00000128
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27607** pertains to a security flaw in the RustFS distributed object storage system, specifically affecting versions **1.0.0-alpha.56 through 1.0.0-alpha.82**. The core issue involves inadequate validation of policy conditions during presigned POST uploads (PostObject). This flaw enables attackers to bypass constraints such as content-length-range, starts-with, and Content-Type, leading to unauthorized file uploads that can exceed size limits, target arbitrary object keys, or spoof content types. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #DDoS https://cvetodo.com/cve/CVE-2026-27607

    Post summary

    The post discloses a RustFS vulnerability (CVE‑2026‑27607) that allows attackers to bypass presigned POST upload restrictions, enabling unauthorized file uploads. No PoC, exploit, patch, or active exploitation is reported.

    0000049
    20 followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-

Explore more