CVE-2025-68926: Critical Hardcoded Credential Flaw Exposes RustFS Storage Clusters
ID: 5846e8b3-b371-5302-b08f-b152a274c66c
STIX ID: report--5846e8b3-b371-5302-b08f-b152a274c66c
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2025-68926) in RustFS exposes a hardcoded, publicly visible gRPC authentication token ('rustfs rpc') that is valid across all default deployments; any attacker with network access to the gRPC port can authenticate using this token and perform privileged actions such as data destruction and cluster configuration changes until the software is patched to support configurable secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
