Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-88018: rclone 1.75.0 allows attackers to impersonate any S3 user

CVE-2026-88018 · published 1 month ago
Summary

The rclone tool, when set up to serve S3 storage with the --auth-proxy option but without specifying an --auth-key, lets a remote attacker pick any access key and sign requests with an empty secret. This lets the attacker access the backend storage that the proxy would normally resolve for that user. Upgrade rclone to version 1.75.1 or later to stop this behavior.

What to do
  • Update rclone to version 1.75.1.
  • Update github.com rclone to version 1.75.1.
  • Update rclone github.com/rclone/rclone to version 1.75.1.
  • Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5.
  • Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5.
  • Update rclone rclone to version 1.75.1 or later.
Affected software
Ecosystem VendorProductAffected versions
– rclone rclone < 1.75.1
Bitnami – rclone < 1.75.1
Fix: upgrade to 1.75.1
go github.com rclone < 1.75.1
Fix: upgrade to 1.75.1
Debian:12 debian rclone All versions
Ubuntu:18.04:LTS canonical rclone All versions
Go rclone github.com/rclone/rclone < 1.75.1
Fix: upgrade to 1.75.1
Root:Go rclone github.com/rclone/rclone < v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5
Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5
Root:Go rclone rootio-github.com/rclone/rclone < v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5
Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5
Original advisory text
CVE-2026-88018 in github.com/rclone/rclone - Patched by Root
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes the access key identifier as both the user and authentication value to the proxy without an independent per-identity secret. An unauthenticated network attacker can therefore choose an arbitrary access key, sign with an empty secret, and reach whatever backend the auth-proxy script resolves for that identity. This issue is fixed in version 1.75.1.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-287Improper Authentication
CWE-306Missing Authentication for Critical Function
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta