Authentication Bypass in rclone Product by the Vendor
CVE-2026-79776
6.9MEDIUM
What is CVE-2026-79776?
rclone versions prior to 1.75.0 expose a security vulnerability where the pprof debug handler is incorrectly configured as a router route. This configuration bypasses the fail-closed authentication that should be enforced in the main handler, allowing unauthenticated attackers to access the /debug/pprof/cmdline endpoint. This can lead to the disclosure of sensitive information, specifically the full process command line arguments, including backend credentials, which significantly increases the risk of unauthorized access to critical system components.
Affected Version(s)
rclone 0 < 1.75.0
rclone 1.75.0
