PT-2026-33833 · Rclone+2 · Rclone+2
0Wnerdied
·
Published
2026-04-20
·
Updated
2026-05-25
·
CVE-2026-41179
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rclone versions 1.48.0 through 1.73.4
Description
The RC endpoint "operations/fsinfo" is exposed without authentication and accepts attacker-controlled
fs input. Since the rc.GetFs() function supports inline backend definitions, an unauthenticated attacker can instantiate a backend on demand. Specifically, for the WebDAV backend, the bearer token command is executed during initialization, allowing for single-request unauthenticated local command execution on reachable RC deployments that lack global HTTP authentication.Recommendations
Update to version 1.73.5.
As a temporary workaround, restrict access to the "operations/fsinfo" endpoint or enable global RC HTTP authentication using
--rc-user, --rc-pass, or --rc-htpasswd to prevent unauthenticated access.Exploit
Fix
OS Command Injection
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Rclone
Ubuntu