Transport Downgrade Vulnerability in rclone by rclone
CVE-2026-79779

6MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79779?

Versions of rclone prior to v1.75.0 contain a vulnerability that allows attackers to exploit transport downgrades during redirect handling. This flaw enables the unauthorized replay of Basic authorization and Cookie headers over plaintext HTTP following HTTPS-to-HTTP redirects within the same host. An on-path attacker can intercept this insecure traffic to capture and reuse sensitive credentials, potentially gaining unauthorized access to WebDAV operations using the compromised account's permissions.

Affected Version(s)

rclone 0 < 1.75.0

rclone 1.75.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberlanc3r
ncw
.