Missing Authentication for Critical Function in rclone - CVE-2026-79776

 

Missing Authentication for Critical Function in rclone - CVE-2026-79776

Published: August 1, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU140647
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-79776
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authentication in the pprof debug handler when handling requests to /debug/pprof/cmdline. A remote attacker can send an unauthenticated request to disclose sensitive information.

The exposed endpoint can reveal the full process command line, including backend credentials passed in argv.


Affected software

rclone

How to mitigate CVE-2026-79776

Install security update from vendor's website.

rclone - update to 1.75.0

External References

Related Security Bulletins