Missing Authentication for Critical Function in rclone - #VU140647

 

Missing Authentication for Critical Function in rclone - #VU140647

Published: August 1, 2026


Vulnerability identifier: #VU140647
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authentication in the pprof debug handler when handling requests to /debug/pprof/cmdline. A remote attacker can send an unauthenticated request to disclose sensitive information.

The exposed endpoint can reveal the full process command line, including backend credentials passed in argv.


Affected software

rclone

Remediation

Install security update from vendor's website.

rclone - update to 1.75.0

External References

Related Security Bulletins