A critical vulnerability, tracked as CVE-2025-68926, was discovered in the RustFS distributed object storage system. The flaw involves the use of a hardcoded static token ("rustfs rpc") for gRPC authentication, which is publicly exposed in the source code and is non-configurable, with no mechanism for token rotation. This token is valid across all RustFS deployments prior to version 1.0.0-alpha.77, allowing any attacker with network access to the gRPC port to authenticate and perform privileged operations such as data destruction, policy manipulation, and cluster configuration changes. The issue has been addressed in version 1.0.0-alpha.77, which removes the hardcoded credential and implements proper authentication controls.
Security researchers have rated this vulnerability as critical, assigning it a CVSS score of 9.8 due to the ease of exploitation and the potential impact on data integrity and availability. Organizations using affected versions of RustFS are strongly advised to upgrade to the patched release immediately to mitigate the risk of unauthorized access and potential compromise of storage clusters. No evidence of exploitation in the wild has been reported as of the latest advisories, but the public nature of the token significantly increases the risk of opportunistic attacks.

Map this exposure pattern across your cloud, code, and identities.
3 events from the most recent confirmed update back to the earliest known activity.
A ProjectDiscovery nuclei-templates pull request was opened to add detection coverage for CVE-2025-68926. The submission noted the issue was verified against RustFS 1.0.0-alpha.76 and referenced GitHub Security Advisory GHSA-h956-rh7x-ppgj.
CVE-2025-68926 was publicly disclosed as a critical vulnerability affecting RustFS versions before 1.0.0-alpha.77. The flaw stems from a hardcoded static gRPC token ('rustfs rpc') that allows remote attackers with network access to bypass authentication and perform privileged operations.
RustFS fixed a critical authentication bypass issue in version 1.0.0-alpha.77 by removing the hardcoded gRPC token from both client and server components. Users were advised to upgrade to this version or later to mitigate the risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcesecurityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.