CVE-2026-41176Disclosure(rclone / rclone)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch rclone rclone systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-15

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rclone

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-04-23); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
rclone

Deep dive

Activity timeline10 mentions / 6d
01345Mentions · 2026-04-20: 1Mentions · 2026-04-23: 5Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-05-12: 1Mentions · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-08: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-23: 2Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-23: 5Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-05-12: 1Technical Details · 2026-09-08: 104-2004-2304-2404-2605-1209-08
Signal classification4 categories
Disclosure
440.0%
Patch
330.0%
General
220.0%
PoC
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-201
Patch1
2026-04-235
Disclosure4General1
2026-04-241
Patch1
2026-04-261
Patch1
2026-05-121
General1
2026-09-081
PoC1
Full discourse10 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - rclone RC auth bypass and unauthenticated backend instantiation enabling remote command execution CVE-2026-41176 - Unauthenticated options/set allows setting rc.NoAuth=true, disabling RC authentication and exposing admin RC methods, leading to full interface compromise. CVE-2026-41179 - Unauthenticated operations/fsinfo enables attacker-controlled backend instantiation via rc.GetFs(). WebDAV init may trigger bearer_token_command, resulting in unauthenticated command execution on exposed RC. 👉Affected: CVE-2026-41176: >= 1.45, <= 1.73.4 | CVE-2026-41179: >= 1.48.0, <= 1.73.4 | Upgrade: 1.73.5

    Post summary

    The post discloses two remote command execution vulnerabilities in rclone’s RC interface and recommends upgrading to v1.73.5 to remediate the issue.

    01060197
    237 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧨CVE-2026-41176 / CVE-2026-41179 — Rclone Remote Control can be flipped into unauthenticated admin and even full RCE via attacker‑controlled backends. If RC is exposed on the edge or in homelabs, treat it as “backup server = remote shell” until you’re on 1.73.5+ with auth locked down. https://nvd.nist.gov/vuln/detail/CVE-2026-41176

    Post summary

    The post alerts about CVE-2026-41176/41179 affecting Rclone Remote Control, noting unauthenticated admin rights that can lead to full RCE, and recommends upgrading to version 1.73.5+ with authentication enabled to mitigate the risk.

    1003094
    1.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41176 - critical 🚨 Rclone RC - Broken Access Control &gt; Rclone &gt;= 1.45.0 and &lt; 1.73.5 contains a broken access control vulnerability caused b... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41176 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑41176 as a critical broken access control flaw in Rclone versions 1.45.0–1.73.4 and links to a project discovery resource for details.

    00012185
    942 followersView on X
  • ET Labs@ET_Labs
    General

    9 new OPEN, 16 new PRO (9 + 7) DOILoader, Outlook Classic Use After Free Remote Code Execution Attempt (CVE-2026-40361), Rclone (CVE-2026-41176, CVE-2026-41179), TA569, Win32/Lumma Stealer https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-12-v11191/3315

    Post summary

    The post lists newly added CVEs to a rule set, indicating recent disclosures, but offers only brief descriptions without detailed exploit, mitigation, or active‑use information.

    01010305
    5.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated auth bypass in `Rclone` (CVE-2026-41176) can lead to sensitive operations and command execution. Restrict network access to `Rclone` remote control interfaces. #Rclone #CVE #InfoSec https://www.pulsepatch.io/posts/cve-2026-41176-rclone-auth-bypass-rce

    Post summary

    The post announces an unauthenticated authentication bypass in Rclone (CVE‑2026‑41176) that permits RCE and offers a mitigation by restricting network access, but it provides no PoC or exploit code.

    0100081
    12 followersView on X
  • キタきつね@foxbook
    PoC

    Rclone Auth Proxy Bypass PoC: Critical CVE-2026-41176 Allows Unauthenticated Command Execution(Rcloneの認証回避脆弱性、未認証でコマンド実行につながるPoCが公開) #SecurityOnline (Sep 7) https://securityonline.info/rclone-auth-proxy-bypass-poc/

    Post summary

    The text announces a proof‑of‑concept demonstrating the CVE‑2026‑41176 Rclone auth proxy bypass that allows unauthenticated command execution; no exploit code, active exploitation, or remediation is provided.

    00000274
    5.0K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 2 critical vulnerabilities in #RClone. CVE-2026-41176 CVSS 9.8 and CVE-2026-41179 CVSS: 9.2. Either could be exploited to execute code. https://ccb.belgium.be/advisories/warning-two-critical-unauthenticated-code-execution-vulnerabilities-rclone-patch #Patch #Patch #Patch

    Post summary

    The advisory announces two critical RClone vulnerabilities (CVE-2026-41176 and CVE-2026-41179) with high CVSS scores that allow code execution. Patches or mitigations are available as indicated by the advisory link and #Patch tags.

    00000149
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41176 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRe… https://www.cve.org/CVERecord?id=CVE-2026-41176

    Post summary

    CVE-2026-41176 is a disclosure of an unauthenticated Rclone RC endpoint, with no PoC, exploit, or patch yet reported.

    0000085
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41176 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41176

    Post summary

    The post announces a new CVE‑2026‑41176 vulnerability in Rclone, detailing an unauthenticated RC endpoint, but provides no proof‑of‑concept, exploitation code, or mitigation advice.

    0000055
    4.0K followersView on X
  • AiSoloStudio@aisolostudio
    General

    RcloneにCriticalな認証バイパス2件(CVE-2026-41176/41179)。未認証でバックエンド操作やコマンド実行が可能。OpenVPN auth-oauth2にも認証バイパス。Django関連は10件以上の修正が集中。本日のGHSA 588件↓ #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-23/

    Post summary

    The post lists critical authentication‑bypass vulnerabilities for Rclone and OpenVPN auth‑oauth2, notes numerous Django fixes today, but offers no PoC, exploit code, or evidence of active exploitation.

    0000096
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprclonerclone---

Explore more