Information disclosure in rclone - #VU140648

 

Information disclosure in rclone - #VU140648

Published: August 1, 2026


Vulnerability identifier: #VU140648
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in serveRoot when handling requests to the root rc endpoint. A remote attacker can send an unauthenticated request to disclose sensitive information.

The issue exposes configured remote names through root endpoint enumeration.


Affected software

rclone

Remediation

Install security update from vendor's website.

rclone - update to 1.75.0

External References

Related Security Bulletins