Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-41179: RClone: Unauthenticated Access to Remote Control API Exposes Local Command Execution

GHSA-jfwf-28xr-xw6q CVE-2026-41179 GHSA-jfwf-28xr-xw6q BIT-rclone-2026-41179
Summary

An attacker without a password can access the RClone remote control API and execute local commands on your system. This can happen if you're using the `--rc` flag or running the `rclone rcd` server and haven't set up global authentication. To fix this, make sure to enable authentication for the remote control API using `--rc-user` and `--rc-pass` or `--rc-htpasswd`.

What to do
  • Update github.com rclone to version 1.73.5.
  • Update rclone github.com/rclone/rclone to version 1.73.5.
  • Update rclone to version 1.73.5.
Affected software
Ecosystem VendorProductAffected versions
go github.com rclone >= 1.48.0, <= 1.73.4
Fix: upgrade to 1.73.5
Go rclone github.com/rclone/rclone >= 1.48.0, < 1.73.5
Fix: upgrade to 1.73.5
rclone rclone >= 1.48.0, < 1.73.5
cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
Bitnami rclone >= 1.48.0, < 1.73.5
Fix: upgrade to 1.73.5
Original title
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Original description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.GetFs(...)` supports inline backend definitions, an unauthenticated attacker can instantiate an attacker-controlled backend on demand. For the WebDAV backend, `bearer_token_command` is executed during backend initialization, making single-request unauthenticated local command execution possible on reachable RC deployments without global HTTP authentication. Version 1.73.5 patches the issue.
ghsa CVSS4.0 9.2
Vulnerability type
CWE-78 OS Command Injection
CWE-306 Missing Authentication for Critical Function
Published: 24 Apr 2026 · Updated: 6 Jul 2026 · First seen: 22 Apr 2026