


Perceptive Security
SOC/SIEM Consultancy

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 sign…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 20:05:25
Source:
nvd.nist.gov
Database & Storage, Supply Chain & Dependencies
RustFS distributed object storage system contains a vulnerability where the internode RPC authentication layer falls back to a hardcoded default secret key 'rustfsadmin' when proper configuration is missing. The vulnerability affects versions prior to 1.0.0-beta.2 and occurs in the get_shared_secret() function in crates/ecstore/src/rpc/http_auth.rs. This allows potential unauthorized access to internode communications using the publicly known default HMAC-SHA256 signature key. The issue is resolved in version 1.0.0-beta.2.
Technical details
Mitigation steps:
Affected products:
RustFS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45039
https://github.com/rustfs/rustfs/security/advisories/GHSA-r5qv-rc46-hv8q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
