CVE-2026-39360 is a missing authorization vulnerability in RustFS, a distributed object storage system written in Rust, affecting versions prior to alpha.90. The flaw exists in the multipart copy functionality (UploadPartCopy), where inadequate access controls allow low-privileged users to exfiltrate objects from victim buckets by copying them into attacker-controlled multipart uploads. This vulnerability compromises tenant isolation in multi-user and multi-tenant deployments. The vulnerability has a CVSS score of 4.3 (Medium) with a network-based attack vector requiring only low-level privileges and no user interaction. The attack is relatively straightforward to execute given the low attack complexity, resulting in limited confidentiality impact through unauthorized data exposure. However, integrity and availability are not affected. This vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities catalog and shows no signs of active exploitation. The EPSS score of 0.0003 indicates extremely low likelihood of exploitation in the wild. Given that RustFS remains in alpha development status, community awareness and adoption are likely limited, reducing the immediate threat landscape. The vulnerability was addressed in alpha.90, and organizations using RustFS should prioritize upgrading to this or later versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha1:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha10:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha11:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha12:*:*:*:rust:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:rustfs:rustfs:1.0.0:alpha13:*:*:*:rust:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.