LOWVulnerability

CVE-2026-73288

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound, unreadable .metadata.bin data, or unparseable metadata as no lock configuration, allowing objects under COMPLIANCE retention to be deleted or expired. This issue is fixed in version 1.0.0-rc.1.

Properties

epss_score
0.00245
cve_id
CVE-2026-73288
published_at
2026-08-12T15:18:32.447
last_modified
2026-09-09T21:02:22.660
epss_percentile
0.15647

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Protection Mechanism Failure
[Weakness]Improper Check for Unusual or Exceptional Conditions

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73288 — Ninja Signal Threat Intelligence | Ninja Signal