RustFS before 1.0.0-alpha.77 used a hardcoded gRPC authentication token "rustfs rpc" that could not be changed without recompiling and this allowed unauthenticated remote attackers to gain full administrative access to the gRPC API.
id: CVE-2025-68926
info:
name: RustFS < 1.0.0-alpha.77 - Hardcoded gRPC Authentication Token
au
...