CVE-2026-41176

EUVD-2026-25142
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
rclonerclone
1.45 ≤
𝑥
< 1.73.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rclone
bookworm
vulnerable
bullseye
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rclone
bionic
not-affected
focal
Fixed 1.50.2-2ubuntu0.2+esm1
released
jammy
Fixed 1.53.3-4ubuntu1.22.04.4
released
noble
Fixed 1.60.1+dfsg-3ubuntu0.24.04.5
released
questing
Fixed 1.60.1+dfsg-4ubuntu2.1
released
resolute
Fixed 1.60.1+dfsg-4ubuntu3.1
released
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
rclone
Amazon Linux 2
0:1.55.1-1.amzn2.0.5
fixed
Amazon Linux 2023
0:1.73.5-75.amzn2023
fixed
rclone-debuginfo
Amazon Linux 2
0:1.55.1-1.amzn2.0.5
fixed
Amazon Linux 2023
0:1.73.5-75.amzn2023
fixed
rclone-debugsource
Amazon Linux 2023
0:1.73.5-75.amzn2023
fixed