CVE-2025-68926 is an authentication-bypass vulnerability in RustFS caused by a static gRPC authentication token embedded in both client and server code. The token is publicly known, non-configurable, non-rotatable, and valid across RustFS deployments. An attacker able to reach the gRPC management endpoint can use it to invoke privileged management operations without legitimate credentials. Affected releases were introduced in the 1.0.0-alpha.13 line; RustFS 1.0.0-alpha.78 contains the reported fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small standalone exploit PoC for CVE-2025-68926 against RustFS. It contains three files: a minimal README, a Bash exploit script (exploit.sh), and a large protobuf service definition (node.proto). The exploit is not part of a larger framework. The main logic is in exploit.sh. It targets a RustFS gRPC NodeService endpoint, defaulting to localhost:9000, and uses grpcurl with the bundled node.proto to call RPC methods directly. The script first verifies that unauthenticated access is rejected, then retries with the hardcoded authorization header 'rustfs rpc'. If the Ping RPC succeeds, it treats the target as vulnerable and proceeds to demonstrate post-bypass impact. Capabilities demonstrated by the script include: server information disclosure (ServerInfo), storage enumeration (LocalStorageInfo), OS/CPU/memory enumeration (GetOsInfo, GetCpus, GetMemInfo), process inspection (GetProcInfo), credential retrieval attempts for a known access key (LoadUser, LoadServiceAccount), and destructive bucket deletion (DeleteBucket). The script also states that the token grants access to 73+ privileged RPC methods. The included node.proto supports that claim by defining a broad NodeService API surface with many sensitive administrative operations, including bucket management, file and volume operations, policy and user management, service signaling, metadata loading/deletion, replication and rebalance controls, and other cluster-management functions. Even though the exploit script only invokes a subset, the proto file shows the wider attack surface available once the hardcoded token is accepted. Operationally, the script is moderately polished: it checks for grpcurl, works around snap confinement by downloading a standalone grpcurl binary from GitHub releases, cleans up temporary files, and prints a step-by-step exploitation summary. This makes it more than a simple detector; it is an operational PoC that actively exercises privileged methods and can perform destructive actions on a vulnerable RustFS deployment.
This repository contains a Go-based exploit for CVE-2025-68926, a vulnerability in RustFS (< 1.0.0-alpha.77) where a hardcoded gRPC authentication token ('rustfs rpc') allows unauthenticated access to all gRPC services. The main exploit logic is implemented in 'main.go', which connects to a user-specified host and port (typically 19010, as mapped in the provided docker-compose.yml) and uses the hardcoded token to authenticate. The exploit programmatically constructs gRPC descriptors for the RustFS NodeService and invokes methods to enumerate disks, list directories, and read arbitrary files from the server. The repository includes setup instructions, a docker-compose file for lab deployment, and references to the vulnerable code locations in RustFS. The attack vector is network-based, targeting the exposed gRPC service. Several endpoints are fingerprintable, including the gRPC service port, S3 API port, console port, and data volume paths. The exploit is operational, providing real file system access and information disclosure on vulnerable RustFS instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named CVE mentioned only in connection with remediation of a stale signature on its Nuclei code template; the underlying vulnerability is not described.
Critical authentication bypass in RustFS caused by a hardcoded, non-rotatable static authentication token shared across deployments; enables administrative access via the exposed gRPC management interface.
A critical authentication bypass vulnerability in RustFS before 1.0.0-alpha.77 due to a hardcoded gRPC authentication token, allowing unauthenticated remote attackers full administrative access.
A critical hardcoded credential vulnerability in RustFS storage clusters that exposes them to unauthorized access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.