PT-2026-33833 · Rclone+2 · Rclone+2

0Wnerdied

·

Published

2026-04-20

·

Updated

2026-05-25

·

CVE-2026-41179

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rclone versions 1.48.0 through 1.73.4
Description The RC endpoint "operations/fsinfo" is exposed without authentication and accepts attacker-controlled fs input. Since the rc.GetFs() function supports inline backend definitions, an unauthenticated attacker can instantiate a backend on demand. Specifically, for the WebDAV backend, the bearer token command is executed during initialization, allowing for single-request unauthenticated local command execution on reachable RC deployments that lack global HTTP authentication.
Recommendations Update to version 1.73.5. As a temporary workaround, restrict access to the "operations/fsinfo" endpoint or enable global RC HTTP authentication using --rc-user, --rc-pass, or --rc-htpasswd to prevent unauthenticated access.

Exploit

Fix

OS Command Injection

Missing Authentication

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-41179
CVE-2026-41179
GHSA-JFWF-28XR-XW6Q
OPENSUSE-SU-2026:10584-1
USN-8299-1

Affected Products

Linuxmint
Rclone
Ubuntu