MEDIUM
RustFS: Unauthenticated RustFS console license endpoint exposes license metadata
Published May 28, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.54%
Description
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentication. The endpoint is registered on the console listener and returns JSON containing license information such as the license subject and expiration timestamp. Any client that can reach the console listener can query this endpoint without credentials. This vulnerability is fixed in 1.0.0-beta.2.
Affected products
-
- Version < 1.0.0-beta.2StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32993 Advisory
- https://github.com/rustfs/rustfs/security/advisories/GHSA-xp32-gxq2-3v52 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-32993 | Advisory | |
| https://github.com/rustfs/rustfs/security/advisories/GHSA-xp32-gxq2-3v52 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 28, 2026
Updated May 28, 2026
Reserved May 18, 2026
Link CVE-2026-47136
CISA Vulnrichment
Updated May 28, 2026
ENISA EUVD
EUVD-2026-32993 Assigner GitHub_M
Published May 28, 2026
Updated May 28, 2026
Exploited since n/a
Link EUVD-2026-32993