PT-2026-81369 · Rclone · Rclone

·

CVE-2026-79780

·

Published

2026-08-05

·

Updated

2026-08-25

CVSS v4.0

6.0

Medium

VectorAV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.75.0
Description The software fails to sanitize IBM IAM bearer tokens and SSE-C (Server-Side Encryption with Customer-Provided Keys) encryption keys during S3 redirect callbacks. This allows credentials to be preserved when there are changes to the scheme or host. An attacker monitoring network traffic from a trusted endpoint can capture reusable IBM IAM tokens during same-host HTTPS-to-HTTP downgrades or capture SSE-C keys during cross-origin redirects to gain unauthorized access to protected S3 objects.
Recommendations Update rclone to version 1.75.0 or later.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79780
GHSA-8MXV-9XHP-86H4
GO-2026-6188

Affected Products

Rclone