PT-2026-57243 · Rclone · Rclone

CVE-2026-59733

·

Published

2026-07-09

·

Updated

2026-09-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.74.4
Description When using the serve restic --private-repos command, the software enforces authorization based on the routed user path segment but constructs the backend object key using the raw, uncleaned URL path. This allows an authenticated user to employ path traversal by including .. in a request, such as //..//config, to read, overwrite, or delete private repositories belonging to other users on backends that clean path components.
Recommendations Update to version 1.74.4.

Exploit

Fix

Path traversal

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-59733
CVE-2026-59733
GHSA-FQJ9-69PF-6PJG
GO-2026-6195
OPENSUSE-SU-2026:11241-1
OPENSUSE-SU-2026:21436-1
OPENSUSE-SU-2026:21761-1

Affected Products

Rclone