Authentication Bypass in rclone Product by the Vendor
CVE-2026-79776

6.9MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79776?

rclone versions prior to 1.75.0 expose a security vulnerability where the pprof debug handler is incorrectly configured as a router route. This configuration bypasses the fail-closed authentication that should be enforced in the main handler, allowing unauthenticated attackers to access the /debug/pprof/cmdline endpoint. This can lead to the disclosure of sensitive information, specifically the full process command line arguments, including backend credentials, which significantly increases the risk of unauthorized access to critical system components.

Affected Version(s)

rclone 0 < 1.75.0

rclone 1.75.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arpitjain099
ncw
.