Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-41179: RClone: Unauthenticated Access to Remote Control API Exposes Local Command Execution
GHSA-jfwf-28xr-xw6q
CVE-2026-41179
GHSA-jfwf-28xr-xw6q
BIT-rclone-2026-41179
Summary
An attacker without a password can access the RClone remote control API and execute local commands on your system. This can happen if you're using the `--rc` flag or running the `rclone rcd` server and haven't set up global authentication. To fix this, make sure to enable authentication for the remote control API using `--rc-user` and `--rc-pass` or `--rc-htpasswd`.
What to do
- Update github.com rclone to version 1.73.5.
- Update rclone github.com/rclone/rclone to version 1.73.5.
- Update rclone to version 1.73.5.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| go | github.com | rclone |
>= 1.48.0, <= 1.73.4 Fix: upgrade to 1.73.5
|
| Go | rclone | github.com/rclone/rclone |
>= 1.48.0, < 1.73.5 Fix: upgrade to 1.73.5
|
| – | rclone | rclone |
>= 1.48.0, < 1.73.5 cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* |
| Bitnami | – | rclone |
>= 1.48.0, < 1.73.5 Fix: upgrade to 1.73.5
|
Original title
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
Original description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.GetFs(...)` supports inline backend definitions, an unauthenticated attacker can instantiate an attacker-controlled backend on demand. For the WebDAV backend, `bearer_token_command` is executed during backend initialization, making single-request unauthenticated local command execution possible on reachable RC deployments without global HTTP authentication. Version 1.73.5 patches the issue.
ghsa CVSS4.0
9.2
Vulnerability type
CWE-78
OS Command Injection
CWE-306
Missing Authentication for Critical Function
- https://github.com/rclone/rclone/security/advisories/GHSA-jfwf-28xr-xw6q
- https://github.com/advisories/GHSA-jfwf-28xr-xw6q
- https://github.com/rclone/rclone Product
- https://github.com/rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/b...
- https://github.com/rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/f...
- https://github.com/rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/f...
- https://nvd.nist.gov/vuln/detail/CVE-2026-41179
- https://github.com/rclone/rclone/commit/2a9e952b38e03a96bf40c9eb6e8e22199865ee3b
- https://github.com/rclone/rclone/releases/tag/v1.73.5
- https://rclone.org/changelog/#v1-73-5-2026-04-19
- https://access.redhat.com/security/cve/CVE-2026-41179 URL
- https://bugzilla.redhat.com/show_bug.cgi?id=2460988 URL
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41179.json URL
Published: 24 Apr 2026 · Updated: 6 Jul 2026 · First seen: 22 Apr 2026