Credential Exposure Vulnerability in rclone by rclone
CVE-2026-79780
6MEDIUM
What is CVE-2026-79780?
Earlier versions of rclone (prior to v1.75.0) do not adequately sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks. This oversight can lead to attackers capturing these sensitive credentials through observation of network traffic from trusted endpoints. Specifically, during HTTPS-to-HTTP downgrades or cross-origin redirects, reusable IBM IAM tokens and SSE-C keys may be exposed, potentially granting unauthorized access to protected S3 objects.
Affected Version(s)
rclone 0 < 1.75.0
rclone 1.75.0
