CVE-2026-55188Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication admin API. The ListRemoteTargetHandler handler for listing remote replication targets only checks whether request credentials exist, but does not verify that the caller has replication or administrator permissions. As a result, an authenticated user with no effective bucket or admin permissions can list remote replication target configuration for a bucket. Because the returned BucketTarget objects include remote target credentials, this can disclose replication access keys and secret keys. This vulnerability is fixed in 1.0.0-beta.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-522CWE-862CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-27); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-27: 2Mentions · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-27: 2Technical Details · 2026-06-29: 106-2706-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-272
Disclosure2
2026-06-291
Disclosure1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication … https://www.cve.org/CVERecord?id=CVE-2026-55188 ----- Traducción: CVE-2026-55188 Rus… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-55188, detailing an authorization bypass vulnerability in RustFS bucket replication, without mentioning PoC, exploits, patches, or active exploitation.

    0001048
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bucket replication … https://www.cve.org/CVERecord?id=CVE-2026-55188

    Post summary

    RustFS versions 1.0.0-alpha.1 to 1.0.0-beta.9 contain an authorization bypass in bucket replication (CVE-2026-55188). The post is an announcement of the vulnerability without any PoC, exploit code, or patch information.

    00010797
    57.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    #CVE-2026-55188 Authorization Bypass in #Rustfs. #CVSS 8.2. Authenticated users can list remote replication targets without proper permissions. No patch available yet. Monitor for updates. #CVEAlert #cybersecurity #infosec #redteam #blueteam #developers More info: https://www.valtersit.com/cve/CVE-2026-55188/

    Post summary

    A new CVE (2026-55188) describing an authorization bypass in Rustfs is disclosed with a CVSS score of 8.2, affecting authenticated users. No patch is currently available, and readers are advised to monitor for updates.

    0000077
    965 followersView on X

Explore more