CVE-2026-27822Disclosure(rustfs / rustfs)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch rustfs rustfs systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an attacker can steal administrator credentials from `localStorage`, leading to full account takeover and system compromise. Version 1.0.0-alpha.83 fixes the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rustfs

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 13 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 7 mentions (2026-02-25); latest day: 1
  • 16 total mentions across 5 days

Affected systems

Vendors
Products
rustfs

1 version affected across 1 product

Deep dive

Activity timeline16 mentions / 5d
02457Mentions · 2026-02-25: 7Mentions · 2026-02-27: 1Mentions · 2026-02-28: 5Mentions · 2026-03-02: 2Mentions · 2026-03-05: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-02: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-25: 7Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-02: 2Technical Details · 2026-03-05: 102-2502-2702-2803-0203-05
Signal classification4 categories
Disclosure
850.0%
Patch
318.8%
General
318.8%
PoC
212.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-257
Disclosure6Patch1
2026-02-271
Patch1
2026-02-285
Disclosure1General3PoC1
2026-03-022
Disclosure1PoC1
2026-03-051
Patch1
Full discourse16 posts
  • Hunter@HunterMapping
    PoC

    🚨Alert🚨 CVE-2026-27822 : Critical XSS Flaw in RustFS Exposes S3 Storage to Total Admin Account Takeovers 🔥PoC:https://github.com/rustfs/rustfs/security/advisories/GHSA-v9fg-3cr2-277j 📊 25K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22RustFS%22 👇Query HUNTER : http://product.name="RustFS" 📰Refer:https://securityonline.info/critical-xss-flaw-in-rustfs-exposes-s3-storage-to-total-admin-account-takeovers/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The tweet alerts to a critical XSS vulnerability in RustFS that could lead to admin account takeover, provides a PoC link, and highlights widespread exposure but does not report active exploitation or a patch.

    18033173.1K
    25.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    RustFS patches a critical 9.1 CVSS XSS flaw (CVE-2026-27822). Attackers can steal S3 credentials via a malicious file preview. Update to 1.0.0-alpha.83 now! #RustFS #CyberSecurity #XSS #CloudSecurity #InfoSec #S3 #RustLang #Vulnerability #PatchAlert https://securityonline.info/critical-xss-flaw-in-rustfs-exposes-s3-storage-to-total-admin-account-takeovers/

    Post summary

    RustFS has released a patch (1.0.0‑alpha.83) for CVE‑2026‑27822, a critical XSS flaw that could let attackers steal S3 credentials through malicious file previews; users are urged to update promptly.

    11053434
    10.4K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical XSS vulnerability in #RustFS Console. CVE-2026-27822 CVSS: 10. A threat actor with low privileges could exploit it to steal credentials, potentially leading to complete admin account takeover and system compromise. #Patch #Patch #Patch

    Post summary

    A critical XSS vulnerability (CVE-2026-27822) in RustFS Console is disclosed with a CVSS score of 10, potentially allowing credential theft and admin takeover.

    01011221
    7.2K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『By bypassing the PDF preview logic, an attacker can steal administrator credentials from localStorage,』 CVE-2026-27822 Critical Stored XSS in Preview Modal leading to Administrative Account Takeover · Advisory · rustfs/rustfs · GitHub https://github.com/rustfs/rustfs/security/advisories/GHSA-v9fg-3cr2-277j

    Post summary

    The advisory announces a critical stored XSS vulnerability in rustfs’s PDF preview modal that can steal admin credentials, but it does not provide a PoC, exploit code, or patch details.

    00011420
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    RustFS Console の脆弱性 CVE-2026-27822 が FIX:Admin アカウントの乗っ取り https://iototsecnews.jp/2026/02/27/stored-xss-vulnerability-in-rustfs-console-puts-s3-admin-credentials-at-risk/ RustFS Console において、管理権限を完全に奪取される恐れのある、きわめて深刻な脆弱性 CVE-2026-27822 (CVSS:10.0) が修正されました。この脆弱性は、管理画面とデータ配信を同じドメイン (同一オリジン) で運用しているという、設計上の不備を突く蓄積型 XSS です。Content-Type を HTML に偽装した悪意のファイルがアップロードされ、そのファイルを管理者がプレビューした瞬間に、ブラウザ内で不正な JavaScript が実行されます。 プレビュー枠と管理画面が同一オリジンであるため、実行されたスクリプトはブラウザの localStorage に保存されている S3 アクセスキーやセッション・トークンなどを制限なく読み取ることが可能です。それにより、攻撃者は管理者の認証情報を盗み出し、システム全体のデータ削除やバックドアの設置など、完全なアカウント乗っ取りを達成します。ご利用のチームは、ご注意ください。 #CVE202627822 #RustFS #Vulnerability

    Post summary

    The article announces that CVE-2026-27822, a critical stored XSS flaw in RustFS Console, has been fixed, detailing how attackers could steal admin credentials, with no report of active exploitation.

    01000177
    483 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical Stored XSS in RustFS Console Leaks Admin S3 Keys (CVE-2026-27822) A stored XSS in RustFS Console’s PDF preview iframe lets attackers upload a “.pdf” with text/html to execute JavaScript on the same origin and steal S3 credentials (AccessKeyId/SecretAccessKey/SessionToken) from localStorage, enabling full admin takeover. Patch by upgrading to 1.0.0-alpha.83 and harden with origin separation + CSP + strict content-type validation. 🎯 Target: Global / RustFS (S3-compatible object storage) admins #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/stored-xss-flaw-in-rustfs-console-leaks-admin-s3-credentials/

    Post summary

    A stored XSS flaw in RustFS Console lets attackers upload a .pdf with HTML to execute JavaScript, steal S3 credentials from localStorage, and take over admin accounts; upgrading to 1.0.0-alpha.83 and applying CSP mitigations resolves the issue.

    0001064
    227 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27822 Stored XSS Vulnerability in RustFS Console Enables Credential Theft https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27822

    Post summary

    The text announces a stored XSS vulnerability (CVE‑2026‑27822) in RustFS Console that can lead to credential theft, but provides no PoC, exploit code, or patch details.

    0001052
    4.0K followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: #RustFSConsole: disponibile un #PoC per lo sfruttamento della CVE-2026-27822 Rischio: 🔴 Tipologia 🔸Arbitrary Code Execution 🔸Information Disclosure 🔗 https://www.acn.gov.it/portale/w/rilevato-poc-in-rustfs-console ⚠️ Ove non provveduto, si raccomanda l’aggiornamento del softw… https://t.co/yJYAHfgbX1

    Post summary

    The tweet announces a PoC for CVE‑2026‑27822, details the vulnerability as arbitrary code execution and information disclosure, recommends a software update, and shows no evidence of active exploitation.

    0000078
    610 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27822 (CVSS:9.0, CRITICAL) is Analyzed. RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Script..https://nvd.nist.gov/vuln/detail/CVE-2026-27822 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑27822, noting its critical CVSS score and that it involves stored cross‑site scripting in RustFS before version 1.0.0‑alpha.83, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    0000047
    173 followersView on X
  • みゃーぎ@popo_myagi
    General

    RustFSの脆弱性 アレコレ出てきて不安になる方がいいのか、使われるようになったからこそアレコレ出てくるのか... まぁ使ってないから対岸の火事的な気持ちなんだけども https://nvd.nist.gov/vuln/detail/CVE-2026-27822

    Post summary

    The user comments on the RustFS vulnerability but provides no technical details, exploit evidence, or patch information.

    00000167
    79 followersView on X
  • VulnTracker@vuln_tracker
    General

    @HunterMapping You now can see the full details about CVE-2026-27822 from https://vulntracker.io/cves/CVE-2026-27822

    Post summary

    The message merely points to a vulnerability tracker page for CVE-2026-27822, providing no additional technical or exploitation details.

    00000144
    352 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full details about CVE-2026-27822 from https://vulntracker.io/cves/CVE-2026-27822

    Post summary

    Tweet directs readers to a vulnerability tracker page for CVE-2026-27822.

    0000051
    352 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27822: RustFS & The PDF Trojan: Anatomy of a Critical Stored XSS While the world rushes to rewrite everything in Rust to escape the nightmare of memory corruption, we are reminded that logic bugs and web vulnerabilities don't care about your ... https://cvereports.com/reports/CVE-2026-27822

    Post summary

    The report announces a critical stored XSS vulnerability in RustFS and the PDF Trojan, providing the vulnerability type but lacking PoC, exploit, or patch details.

    0000062
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27822 RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console … https://www.cve.org/CVERecord?id=CVE-2026-27822

    Post summary

    The text announces a stored XSS vulnerability in RustFS Console prior to version 1.0.0‑alpha.83, as recorded in CVE‑2026‑27822.

    00000179
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27822: CRITICAL] RustFS 1.0.0-alpha.83 addresses a Stored XSS vulnerability in its management console, protecting against JavaScript execution and possible admin credential theft in previous versions.#cve,CVE-2026-27822,#cybersecurity https://cvefind.com/CVE-2026-27822

    Post summary

    RustFS released version 1.0.0‑alpha.83 to fix a critical stored XSS flaw in its management console, preventing JavaScript execution and potential admin credential theft.

    0000067
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27822** is a critical Stored Cross-Site Scripting (XSS) vulnerability present in versions of RustFS prior to 1.0.0-alpha.83. RustFS is a distributed object storage system built in Rust, and this vulnerability specifically affects its management console interface. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #XSS https://cvetodo.com/cve/CVE-2026-27822

    Post summary

    A critical stored XSS vulnerability (CVE‑2026‑27822) affects RustFS versions before 1.0.0‑alpha.83, impacting the management console.

    0000095
    20 followersView on X
CPE platform detail82 entries

82 of 82 entries

PartVendorProductVersionTarget SWTarget HW
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-
Apprustfsrustfs1.0.0rust-

Explore more