Security Flaw in Rclone Affects File Syncing with Cloud Storage
CVE-2026-88044

9.1CRITICAL

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88044?

Rclone, a command-line tool for syncing files with cloud storage, suffered from a flaw in versions 1.70.0 to 1.75.1 that impacts its handling of authentication proxies. When the global proxy setting for authentication is empty, local authentication proxies are ignored, which leads to security vulnerabilities in FTP and S3 requests. Users may inadvertently access unsecured resources, as FTP falls back to an anonymous mode and S3 defaults to a fixed filesystem instead of adhering to set configurations. This issue was addressed in version 1.75.1.

Affected Version(s)

rclone >= 1.70.0, < 1.75.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.