CVE-2026-49980

Aliases:GHSA-qw24-gh76-8rvvBIT-rclone-2026-49980UBUNTU-CVE-2026-49980DEBIAN-CVE-2026-49980GO-2026-5596CGA-4vx7-q8h5-vr27CGA-4xj7-q8hc-vv3rCGA-gqjj-7j36-mg2cCGA-pcjm-4wf8-2qpcCGA-39jm-q3c6-qv79CGA-v2f9-c6pc-vp8wCGA-v2q4-g3w3-ch6mCGA-x4pr-9v6c-rj9mUSN-8782-1
Modified
Published: 24 Jun 2026, 17:52
Last modified:10 Aug 2026, 12:05

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
0.74% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Jun 2026, 17:52
Published
Vulnerability first disclosed
10 Aug 2026, 12:05
Last Modified
Vulnerability information updated

Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.74% Percentile: 53%

Techniques & Countermeasures

  • CWE-306Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • chainguardtelegraf-1.36

    all

  • chainguardtelegraf-1.37

    all

  • chainguardtelegraf-1.38

    < 1.38.4-r19

  • chainguardtelegraf-1.39

    < 1.39.2-r3

  • wolfitelegraf-1.36

    all

  • wolfitelegraf-1.37

    all

  • wolfitelegraf-1.38

    < 1.38.4-r19

  • debianrclone

    all | all | all

  • ubunturclone

    all | all | all | < 1.53.3-4ubuntu1.22.04.5 | < 1.60.1+dfsg-3ubuntu0.24.04.6 | < 1.60.1+dfsg-4ubuntu3.2

  • github.com/ncwrclone

    ≥ 1.46.0

  • github.com/rclonerclone

    ≥ 1.49.0, < 1.74.3 | ≥ 1.46.0, < 1.74.3

  • rclonerclone

    ≥ 1.46.0, < 1.74.3 | ≥ 1.46, < 1.74.3

References (13)