Exposure of Data Element to Wrong Session in rclone - #VU147306
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose and modify data exposed by another backend.
The vulnerability exists due to exposure of a data element to the wrong session in the FTP auth-proxy driver\'s username-global credential map when handling subsequent FTP filesystem operations. A remote user can perform an operation after another user logs in with the same username and a different credential to disclose and modify data exposed by another backend.
Exploitation requires an auth-proxy deployment that accepts distinct credentials for the same username and maps them to different backend authorities.