A vulnerability categorized as critical has been discovered in RustFS up to 1.0.0-beta.10 . This vulnerability affects the function AddServiceAccount of the file rustfs/src/admin/handlers/service_account.rs of the component Service Account . The manipulation of the argument target_user results in improper privilege management. This vulnerability is known as CVE-2026-73284 . It is possible to launch the attack remotely. No exploit is available. It is advisable to upgrade the affected component.