HIGH🇵🇱 Wersja polska

CVE-2026-59733

CVSS 8.8v3.1pub. 2026-07-14upd. 2026-07-29

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Rclone

    APP
    Rclone
    < 1.74.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-49980CRITICAL9.8PL ✓same product

Rclone RCD: nieuwierzytelniony command injection przez inline konfigurację zdalną

CVE-2026-41176CRITICAL9.2PL ✓same product

Rclone RC: pominięcie uwierzytelnienia przez endpoint options/set

CVE-2026-41179CRITICAL9.2PL ✓same product

Rclone: nieuwierzytelnione RCE przez endpoint RC operations/fsinfo

CVE-2026-54572HIGH7.5PL ✓same product

Rclone: ucieczka poza katalog docelowy przez niezweryfikowany symlink

CVE-2020-28924HIGH7.5same product

An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the passwor...