Authentication Bypass Vulnerability in rclone by Rclone
CVE-2026-88018

9.8CRITICAL

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88018?

An authentication bypass vulnerability in rclone allows attackers to exploit the command-line program configured with --auth-proxy but without --auth-key. Prior to the release of version 1.75.1, the configuration inadvertently permits attackers to register any client-chosen accessKeyID with an empty s3Secret. This means that an unauthenticated attacker can sign requests using an empty secret and access the backend associated with the specified identity. The issue has been addressed in version 1.75.1, highlighting the importance of keeping software up to date to mitigate security risks.

Affected Version(s)

rclone < 1.75.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.