← All CVEs

CVE-2026-27822

critical · 9

RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF preview logic, an attacker can steal administrator credentials from `localStorage`, leading to full account takeover and system compromise. Version 1.0.0-alpha.83 fixes the issue.

9
CVSS
4.2%
EPSS (exploit prob.)
91st
EPSS percentile
2026-02-25
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Weaknesses

CWE-79

Affected products

VendorProductAffected versions
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0
rustfsrustfs1.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-27822