CVE-2026-79776
EUVD-2026-6553425.08.2026, 16:17
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rclone | rclone | 𝑥 < 1.75.0 | CNA |
Common Weakness Enumeration