Incorrect Privilege Assignment Affecting rustfs package, versions *


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Privilege Assignment vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-RUST-RUSTFS-14912637
  • published11 Jan 2026
  • disclosed8 Jan 2026
  • creditUnknown

Introduced: 8 Jan 2026

NewCVE-2026-22042  (opens in a new tab)
CWE-266  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

rustfs is a high-performance distributed object storage software built using Rust, one of the most popular languages worldwide. Along with MinIO, it shares a range of advantages such as simplicity, S3 compatibility, open-source nature, support for data lakes, AI, and big data. Furthermore, it has a better and more user-friendly open-source license in comparison to other storage systems, being constructed under the Apache license.

Affected versions of this package are vulnerable to Incorrect Privilege Assignment via the ImportIam process. An attacker can gain unauthorized access to modify IAM entities by exploiting improper authorization checks that validate export permissions instead of import permissions.

CVSS Base Scores

version 4.0
version 3.1