Skip to content
Stored XSS Vulnerability in RustFS Console Exposes Admin S3 Credentials

Stored XSS Vulnerability in RustFS Console Exposes Admin S3 Credentials

First seen 28 Feb 2026, 18:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A stored cross-site scripting (XSS) vulnerability in the RustFS Console has been identified, allowing attackers to steal admin S3 credentials. This flaw poses a significant risk of full account takeovers for affected users. The issue was reported on February 27, 2026, and has been confirmed by multiple cybersecurity sources.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

Timeline

2026-02-27
Vulnerability reported in RustFS Console
2026-02-28
Cyberpress publishes details on the XSS flaw

More articles in this cluster (2)