Credential Exposure Vulnerability in rclone by rclone
CVE-2026-79780

6MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79780?

Earlier versions of rclone (prior to v1.75.0) do not adequately sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks. This oversight can lead to attackers capturing these sensitive credentials through observation of network traffic from trusted endpoints. Specifically, during HTTPS-to-HTTP downgrades or cross-origin redirects, reusable IBM IAM tokens and SSE-C keys may be exposed, potentially granting unauthorized access to protected S3 objects.

Affected Version(s)

rclone 0 < 1.75.0

rclone 1.75.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cyberlanc3r
ncw
.