Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-88044: rclone 1.70.0‑1.75.1 may allow anonymous FTP or wrong storage access
CVE-2026-88044 · published 29 days ago
Summary
Versions of rclone from 1.70.0 through 1.75.1 have a mistake in the way they handle authentication settings for its built‑in FTP and S3 servers. When the global authentication option is left empty, the servers can fall back to an open "anonymous" login or serve the wrong storage area, letting anyone connect and see or modify data. Upgrade rclone to version 1.75.1 or later to correct the handling of authentication settings.
What to do
- Update github.com rclone to version 1.75.1.
- Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3.
- Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3.
- Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.4.
- Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.4.
- Update rclone github.com/rclone/rclone to version 1.75.1.
- Update rclone to version 1.75.1.
- Update rclone github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5.
- Update rclone rootio-github.com/rclone/rclone to version v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rclone | rclone | >= 1.70.0, < 1.75.1 |
| go | github.com | rclone |
>= 1.70.0, < 1.75.1 Fix: upgrade to 1.75.1
|
| Debian:12 | debian | rclone | All versions |
| Ubuntu:18.04:LTS | canonical | rclone | All versions |
| Root:Go | rclone | github.com/rclone/rclone |
< v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3 < v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.4 < v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.5 Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-aikido.3
|
| Root:Go | rclone | rootio-github.com/rclone/rclone |
< v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3 < v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.4 < v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.5 Fix: upgrade to v1.74.1-0.20260628215305-6bbc28cf02dc-root.io.3
|
| Go | rclone | github.com/rclone/rclone |
>= 1.70.0, < 1.75.1 Fix: upgrade to 1.75.1
|
| Bitnami | – | rclone |
>= 1.70.0, < 1.75.1 Fix: upgrade to 1.75.1
|
Original advisory text
CVE-2026-88044 in github.com/rclone/rclone - Patched by Root
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and cmd/serve/s3/server.go incorrectly check the process-global proxy.Opt.AuthProxy value instead. When the global value is empty, the request-local authentication proxy is ignored: FTP falls back to the fixed filesystem with username anonymous and any password, while S3 with AuthKey serves the fixed RC fs rather than the backend selected by the proxy. The dedicated command-line servers that configure the global option are not affected. This issue is fixed in version 1.75.1.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-88044
- https://github.com/advisories/GHSA-p569-5gjg-9cmj
- https://security-tracker.debian.org/tracker/CVE-2026-88044 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88044... Vendor Advisory
- https://ubuntu.com/security/CVE-2026-88044 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-88044 Third Party Advisory
- https://github.com/rclone/rclone Product
- https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153
- https://github.com/rclone/rclone/releases/tag/v1.75.1
- https://github.com/rclone/rclone/security/advisories/GHSA-p569-5gjg-9cmj
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-863Incorrect Authorization
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-88044 · NVD
CVE-2026-88044 · MITRE
GHSA-p569-5gjg-9cmj · GHSA
DEBIAN-CVE-2026-88044 · OSV
UBUNTU-CVE-2026-88044 · OSV
CVE-2026-88044 · OSV
GO-2026-6460 · OSV
GHSA-p569-5gjg-9cmj · OSV
BIT-rclone-2026-88044 · OSV
Track software like this
Free during beta