A vulnerability marked as critical has been reported in RustFS. The affected element is the function
maybe_merge_object_tag_conditions of the file crates/iam/src/sys.rs of the component IAM. Performing a manipulation results in improper authorization.
This vulnerability was named CVE-2026-73285. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.