CVE-2026-73288

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as no lock configuration, allowing objects under COMPLIANCE retention to be deleted or expired. This issue is fixed in version 1.0.0-rc.1.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 15:18

Updated : 2026-09-09 21:02


NVD link : CVE-2026-73288

Mitre link : CVE-2026-73288

CVE.ORG link : CVE-2026-73288


JSON object : View

Products Affected

No product.

CWE
CWE-693

Protection Mechanism Failure

CWE-754

Improper Check for Unusual or Exceptional Conditions