logo

CVE-2025-68926: Critical Hardcoded Credential Flaw Exposes RustFS Storage Clusters

ID: 5846e8b3-b371-5302-b08f-b152a274c66c

STIX ID: report--5846e8b3-b371-5302-b08f-b152a274c66c

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-01-02

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical vulnerability (CVE-2025-68926) in RustFS exposes a hardcoded, publicly visible gRPC authentication token ('rustfs rpc') that is valid across all default deployments; any attacker with network access to the gRPC port can authenticate using this token and perform privileged actions such as data destruction and cluster configuration changes until the software is patched to support configurable secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.