PT-2026-68328 · Rclone · Rclone

CVE-2026-71309

·

Published

2026-08-05

·

Updated

2026-09-04

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rclone versions 1.40.0 through 1.74.0
Description The serve restic command fails to properly reject URL paths starting with ../ in the WithRemote function within cmd/serve/restic/restic.go. This allows a leading parent path to be passed to GET, HEAD, POST, and DELETE handlers for backends such as WebDAV, FTP, HTTP, Memory, and SFTP. An attacker with access to the REST endpoint can read, create, overwrite, or delete objects outside the operator's configured path if the backend credentials have access to parent or sibling objects.
Recommendations Update to version 1.75.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-RCLONE-2026-71309
CVE-2026-71309
GHSA-45PQ-889G-FCGH
GO-2026-6184
OPENSUSE-SU-2026:21761-1

Affected Products

Rclone