PT-2026-81365 · Rclone · Rclone

·

CVE-2026-79776

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.0
Description The software mounts the pprof debug handler as its own router route, which bypasses the fail-closed authentication rule in the main handler. This allows unauthenticated access to the '/debug/pprof/cmdline' endpoint, enabling the retrieval of the full process argv, which may include backend credentials.
Recommendations Update rclone to version 1.75.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79776
GHSA-MFVX-7RCJ-9M5G

Affected Products

Rclone