{"id":"CVE-2026-73285","summary":"RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged","details":"RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa, causing maybe_merge_object_tag_conditions to omit s3:ExistingObjectTag/* values and allowing authenticated users to bypass tag-based policy restrictions. This issue is fixed in version 1.0.0-rc.1.","aliases":["GHSA-5w8r-p896-6vq2"],"modified":"2026-09-11T03:48:37.355566439Z","published":"2026-08-12T14:37:42.271Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73285.json"},"references":[{"type":"WEB","url":"https://github.com/rustfs/rustfs/releases/tag/1.0.0-rc.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73285.json"},{"type":"ADVISORY","url":"https://github.com/rustfs/rustfs/blob/380ed40b471887014fe21d069b61df9eacca074b/.agents/skills/security-advisory-lessons/references/advisory-patterns.md?plain=1#L47"},{"type":"ADVISORY","url":"https://github.com/rustfs/rustfs/security/advisories/GHSA-5w8r-p896-6vq2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73285"},{"type":"FIX","url":"https://github.com/rustfs/rustfs/commit/98d3619613722308498494d412797a52ea8ae64d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rustfs/rustfs","events":[{"introduced":"7f24dbda198f4a9c6d73728dcb07710fb1b14c12"},{"fixed":"98d3619613722308498494d412797a52ea8ae64d"},{"fixed":"778f1dfa2155cbbc61ad54e6896de9e29d2c4d8d"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0-alpha.64"},{"fixed":"1.0.0-rc.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.0.0-beta.12-preview.1","1.0.0-beta.12","1.0.0-beta.11-preview.1","1.0.0-beta.11","1.0.0-beta.10-preview.5","1.0.0-beta.10","1.0.0-beta.10-preview.4","1.0.0-beta.10-preview.3","1.0.0-beta.10-preview.2","1.0.0-beta.10-preview.1","1.0.0-beta.9","1.0.0-beta.8","1.0.0-beta.7","1.0.0-beta.6","1.0.0-beta.5","1.0.0-beta.4","1.0.0-beta.3","1.0.0-beta.2","v1.0.0-beta.1","1.0.0-beta.1","1.0.0-alpha.99","1.0.0-alpha.98","1.0.0-alpha.97","1.0.0-alpha.96","1.0.0-alpha.95","1.0.0-alpha.94","1.0.0-alpha.93","1.0.0-alpha.92","1.0.0-alpha.91","1.0.0-alpha.90","1.0.0-alpha.89","1.0.0-alpha.88","1.0.0-alpha.87","1.0.0-alpha.86","1.0.0-alpha.85","1.0.0-alpha.84","1.0.0-alpha.83","1.0.0-alpha.82","1.0.0-alpha.81","1.0.0-alpha.80","1.0.0-alpha.79","1.0.0-alpha.78","1.0.0-alpha.77","1.0.0-alpha.76","1.0.0-alpha.75","1.0.0-alpha.74","1.0.0-alpha.73","1.0.0-alpha.72","1.0.0-alpha.71","1.0.0-alpha.70","1.0.0-alpha.69","1.0.0-alpha.68","1.0.0-alpha.67","1.0.0-alpha.66","1.0.0-alpha.65","1.0.0-alpha.64"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73285.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}