RustFS disclosed and fixed CVE-2026-73284, an improper privilege management flaw in the AddServiceAccount handler that could let an authenticated low-privilege user create a service account tied to the root credential. The vulnerable logic checked only CreateServiceAccountAdminAction and accepted an attacker-controlled target_user, which was then passed into service-account creation without confirming that the requested parent account was within the caller’s scope. RustFS said the resulting account could be marked as owner-authenticated through prepare_service_account_auth, creating a path to full compromise of confidentiality, integrity, and availability.
The issue is tracked as GHSA-5354 and carries a CVSS 3.1 score of 9.1 with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Maintainers addressed the bug in RustFS 1.0.0-beta.11 by adding scope enforcement so non-owners can create service accounts only for themselves or, when using derived credentials, for their own parent account, while owners retain broader cross-user creation rights. The project also merged regression tests covering both the original non-owner abuse case and derived-credential attack scenarios to prevent the authorization bypass from reappearing.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for the RustFS privilege-management flaw was received by security-advisories@github.com. The issue describes how AddServiceAccount could be abused to create a root-parent service account that authenticates as the owner.
RustFS merged pull request #5141 as commit 9866f68, fixing improper authorization in AddServiceAccount by enforcing that non-owners can create service accounts only within their own scope. The change also added regression testing for the issue tracked as GHSA-5354-r3w2-34m8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.