CVE-2026-41179Patch(rclone / rclone)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch rclone rclone systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` input. Because `rc.GetFs(...)` supports inline backend definitions, an unauthenticated attacker can instantiate an attacker-controlled backend on demand. For the WebDAV backend, `bearer_token_command` is executed during backend initialization, making single-request unauthenticated local command execution possible on reachable RC deployments without global HTTP authentication. Version 1.73.5 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-306CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rclone

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 4 mentions (2026-04-23); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
rclone

Deep dive

Activity timeline9 mentions / 6d
01234Mentions · 2026-04-20: 1Mentions · 2026-04-23: 4Mentions · 2026-04-24: 1Mentions · 2026-04-26: 1Mentions · 2026-05-12: 1Mentions · 2026-06-17: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-23: 3Technical Details · 2026-04-24: 1Technical Details · 2026-04-26: 1Technical Details · 2026-06-17: 104-2004-2304-2404-2605-1206-17
Signal classification3 categories
Patch
444.4%
General
333.3%
Disclosure
222.2%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-201
Patch1
2026-04-234
Disclosure2General2
2026-04-241
Patch1
2026-04-261
Patch1
2026-05-121
General1
2026-06-171
Patch1
Full discourse9 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - rclone RC auth bypass and unauthenticated backend instantiation enabling remote command execution CVE-2026-41176 - Unauthenticated options/set allows setting rc.NoAuth=true, disabling RC authentication and exposing admin RC methods, leading to full interface compromise. CVE-2026-41179 - Unauthenticated operations/fsinfo enables attacker-controlled backend instantiation via rc.GetFs(). WebDAV init may trigger bearer_token_command, resulting in unauthenticated command execution on exposed RC. 👉Affected: CVE-2026-41176: >= 1.45, <= 1.73.4 | CVE-2026-41179: >= 1.48.0, <= 1.73.4 | Upgrade: 1.73.5

    Post summary

    The post discloses details of CVE-2026-41176 and CVE-2026-41179, explains the remote command execution risk, and recommends upgrading to version 1.73.5 to remediate the issue.

    01060197
    237 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-41179 - critical 🚨 RClone RC - Command Injection &gt; Rclone &gt;= 1.48.0 and &lt; 1.73.5 contains an unauthenticated local command execution cau... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41179 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE-2026-41179 is a critical command injection vulnerability in RClone versions 1.48.0–1.73.4 that allows unauthenticated local command execution; a ProjectDiscovery library link is provided for further details.

    01022167
    942 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧨CVE-2026-41176 / CVE-2026-41179 — Rclone Remote Control can be flipped into unauthenticated admin and even full RCE via attacker‑controlled backends. If RC is exposed on the edge or in homelabs, treat it as “backup server = remote shell” until you’re on 1.73.5+ with auth locked down. https://nvd.nist.gov/vuln/detail/CVE-2026-41176

    Post summary

    The post highlights CVE‑2026‑41176/CVE‑2026‑41179, which allow unauthenticated admin rights and full remote code execution on Rclone Remote Control. Users are urged to update to version 1.73.5+ and enforce authentication to mitigate the risk.

    1003094
    1.7K followersView on X
  • ET Labs@ET_Labs
    General

    9 new OPEN, 16 new PRO (9 + 7) DOILoader, Outlook Classic Use After Free Remote Code Execution Attempt (CVE-2026-40361), Rclone (CVE-2026-41176, CVE-2026-41179), TA569, Win32/Lumma Stealer https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-12-v11191/3315

    Post summary

    The text announces a list of new CVEs without providing additional details or evidence of exploitation or mitigation.

    01010305
    5.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `RClone` is affected by an unauthenticated remote command execution vulnerability (CVE-2026-41179) via operations/fsinfo. This allows attacker-controlled backend instantiation. #RClone #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-41179-rclone-unauthenticated-rce

    Post summary

    The tweet alerts that RClone suffers from an unauthenticated RCE (CVE‑2026‑41179) via operations/fsinfo, enabling attacker‑controlled backend instantiation, but does not indicate active exploitation, patch availability, or the existence of a PoC.

    01001121
    12 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - rclone Unauthenticated Command Execution via rcd --rc-serve (CVE-2026-49980) rclone's rcd --rc-serve mode allows unauthenticated GET/HEAD requests that trigger inline remote instantiation. This bypasses the previous fix (CVE-2026-41179) and enables remote attackers to execute arbitrary commands as the rclone process user. 👉 Affected: rclone >= 1.46.0, <= 1.74.2 | Upgrade to 1.74.3

    Post summary

    The text announces a high‑severity unauthenticated remote command execution flaw in rclone’s rcd --rc‑serve mode, details how it works, and recommends upgrading to 1.74.3 to fix it.

    00000105
    217 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: 2 critical vulnerabilities in #RClone. CVE-2026-41176 CVSS 9.8 and CVE-2026-41179 CVSS: 9.2. Either could be exploited to execute code. https://ccb.belgium.be/advisories/warning-two-critical-unauthenticated-code-execution-vulnerabilities-rclone-patch #Patch #Patch #Patch

    Post summary

    The advisory alerts to two high‑severity, unauthenticated code‑execution vulnerabilities in RClone and references patch information.

    00000149
    7.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41179 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, … https://www.cve.org/CVERecord?id=CVE-2026-41179

    Post summary

    The post references CVE-2026-41179 and mentions affected Rclone version ranges but provides no additional detail such as proof‑of‑concept, exploit code, active exploitation, or mitigations.

    0000080
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41179 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsin... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41179

    Post summary

    The entry references CVE-2026-41179 affecting Rclone versions 1.48.0 to 1.73.5, highlighting the problematic `operations/fsin` endpoint, but does not disclose exploitation details or solutions.

    0000057
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprclonerclone---

Explore more