PT-2026-81371 · Rclone · Rclone

·

CVE-2026-79782

·

Published

2026-08-05

·

Updated

2026-08-28

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rclone versions prior to 1.74.4
Description The software fails to strip the X-Amz-Security-Token header when an S3 redirect changes the scheme from HTTPS to HTTP on the same host. This allows attackers to intercept plaintext HTTP traffic and capture AWS Security Token Service (STS) session tokens sent in request headers.
Recommendations Update rclone to version 1.74.4 or later.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79782
GHSA-GX4C-2HQX-CW2R
GO-2026-6196

Affected Products

Rclone