PT-2026-71091 · Rustfs · Rustfs

CVE-2026-73288

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v4.0

6.1

Medium

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RustFS versions prior to 1.0.0-rc.1
Description Object Lock enforcement in the crates/ecstore/src/bucket/object lock/objectlock sys.rs file incorrectly handles certain error conditions. Specifically, the functions check object lock for deletion(), delete prefix(), and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as if no lock configuration exists. This allows objects under COMPLIANCE retention—a strict Write Once Read Many (WORM) state that prevents deletion—to be deleted or expired.
Recommendations Update to version 1.0.0-rc.1.

Exploit

Fix

Protection Mechanism Failure

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73288
GHSA-J548-9GRX-FH4F

Affected Products

Rustfs