Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-88044: rclone 1.70.0‑1.75.1 may allow anonymous FTP or wrong storage access

CVE-2026-88044 · published 29 days ago
Summary

Versions of rclone from 1.70.0 through 1.75.1 have a mistake in the way they handle authentication settings for its built‑in FTP and S3 servers. When the global authentication option is left empty, the servers can fall back to an open "anonymous" login or serve the wrong storage area, letting anyone connect and see or modify data. Upgrade rclone to version 1.75.1 or later to correct the handling of authentication settings.

What to do
  • Update github.com rclone to version 1.75.1.
  • Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3.
  • Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3.
  • Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.4.
  • Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.4.
  • Update rclone github.com/rclone/rclone to version 1.75.1.
  • Update rclone to version 1.75.1.
  • Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5.
  • Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5.
Affected software
Ecosystem VendorProductAffected versions
– rclone rclone >= 1.70.0, < 1.75.1
go github.com rclone >= 1.70.0, < 1.75.1
Fix: upgrade to 1.75.1
Debian:12 debian rclone All versions
Ubuntu:18.04:LTS canonical rclone All versions
Root:Go rclone github.com/rclone/rclone < v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3
< v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.4
< v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5
Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3
Root:Go rclone rootio-github.com/rclone/rclone < v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3
< v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.4
< v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5
Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3
Go rclone github.com/rclone/rclone >= 1.70.0, < 1.75.1
Fix: upgrade to 1.75.1
Bitnami – rclone >= 1.70.0, < 1.75.1
Fix: upgrade to 1.75.1
Original advisory text
CVE-2026-88044 in github.com/rclone/rclone - Patched by Root
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and cmd/serve/s3/server.go incorrectly check the process-global proxy.Opt.AuthProxy value instead. When the global value is empty, the request-local authentication proxy is ignored: FTP falls back to the fixed filesystem with username anonymous and any password, while S3 with AuthKey serves the fixed RC fs rather than the backend selected by the proxy. The dedicated command-line servers that configure the global option are not affected. This issue is fixed in version 1.75.1.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-863Incorrect Authorization
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta