Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rustfs
Rustfs rustfs |
|
| Vendors & Products |
Rustfs
Rustfs rustfs |
Fri, 29 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create service accounts under arbitrary parent identities, including the root user (minioadmin). The endpoint accepts attacker-controlled parent, claims, accessKey, and secretKey values without enforcing privilege boundaries or sanitization. This enables privilege escalation to full administrative access using a persistent, attacker-defined credential. This vulnerability is fixed in 1.0.0-beta.2. | |
| Title | RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including Root | |
| Weaknesses | CWE-269 CWE-284 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T01:08:47.243Z
Reserved: 2026-05-08T18:07:27.341Z
Link: CVE-2026-45043
Updated: 2026-06-02T01:06:47.236Z
Status : Deferred
Published: 2026-05-29T13:16:22.630
Modified: 2026-06-02T02:16:15.930
Link: CVE-2026-45043
No data.
OpenCVE Enrichment
Updated: 2026-05-29T14:00:20Z