A vulnerability marked as critical has been reported in RustFS . The affected element is the function maybe_merge_object_tag_conditions of the file crates/iam/src/sys.rs of the component IAM . Performing a manipulation results in improper authorization. This vulnerability was named CVE-2026-73285 . The attack may be initiated remotely. There is no available exploit. It is suggested to upgrade the affected component.