Security Flaw in Rclone Affects File Syncing with Cloud Storage
CVE-2026-88044
9.1CRITICAL
What is CVE-2026-88044?
Rclone, a command-line tool for syncing files with cloud storage, suffered from a flaw in versions 1.70.0 to 1.75.1 that impacts its handling of authentication proxies. When the global proxy setting for authentication is empty, local authentication proxies are ignored, which leads to security vulnerabilities in FTP and S3 requests. Users may inadvertently access unsecured resources, as FTP falls back to an anonymous mode and S3 defaults to a fixed filesystem instead of adhering to set configurations. This issue was addressed in version 1.75.1.
Affected Version(s)
rclone >= 1.70.0, < 1.75.1
