rclone records
14 published records for vendor rclone.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 92.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-306 Missing Authentication for Critical Function2
- CWE-190 Integer Overflow or Wraparound1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-49980No exploit | Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixrclone · rclone · CWE-306 | Critical9.8 | — | 0.8% | Jun 24, 2026 |
39Monitor | CVE-2026-88018No exploit | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassrclone · rclone · CWE-287 | Critical9.8 | — | 0.8% | Sep 10, 2026 |
38Monitor | CVE-2026-41179Proof of concept | RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionrclone · rclone · CWE-78 | Critical9.2 | — | 5.3% | Apr 22, 2026 |
37Monitor | CVE-2026-41176Proof of concept | Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionrclone · rclone · CWE-306 | Critical9.2 | — | 3.2% | Apr 22, 2026 |
35Monitor | CVE-2026-59733No exploit | rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesrclone · rclone · CWE-22 | High8.8 | — | 0.6% | Jul 14, 2026 |
35Monitor | CVE-2026-54572No exploit | rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoterclone · rclone · CWE-59 | High8.8 | — | 0.4% | Jul 14, 2026 |
30Monitor | CVE-2020-28924No exploit | An issue was discovered in Rclone before 1.53.3.rclone · rclone · CWE-331 | High7.5 | — | 1.4% | Nov 19, 2020 |
30Monitor | CVE-2018-12907No exploit | In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmissrclone · rclone · CWE-200 | High7.5 | — | 1.3% | Jun 27, 2018 |
29Monitor | CVE-2026-88017No exploit | rclone: FTP cross-session auth-proxy backend confusionrclone · rclone · CWE-488 | High7.3 | — | 0.4% | Sep 10, 2026 |
28Monitor | CVE-2026-88016No exploit | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destinationrclone · rclone · CWE-59 | High7.1 | — | 0.3% | Sep 10, 2026 |
25Monitor | CVE-2026-88014No exploit | rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespacerclone · rclone · CWE-22 | Medium6.3 | — | 0.2% | Sep 10, 2026 |
21Monitor | CVE-2026-88015No exploit | rclone local: crafted Range request against a translated symlink panics (DoS)rclone · rclone · CWE-190 | Medium5.3 | — | 0.5% | Sep 10, 2026 |
21Monitor | CVE-2026-88013No exploit | rclone: http backend forwards custom/auth headers to a different host on redirectrclone · rclone · CWE-200 | Medium5.3 | — | 0.2% | Sep 10, 2026 |
20Monitor | CVE-2026-59732No exploit | rclone archive extract allows S3 destination prefix escape via crafted archive pathsrclone · rclone · CWE-22 | Medium5.0 | — | 0.2% | Jul 14, 2026 |
- CVE-2026-4998039Monitor
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
CriticalCVSS 9.8No exploitEPSS 1%rclone · rcloneJun 24, 2026
- CVE-2026-8801839Monitor
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
CriticalCVSS 9.8No exploitEPSS 1%rclone · rcloneSep 10, 2026
- CVE-2026-4117938Monitor
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CriticalCVSS 9.2Proof of conceptEPSS 5%rclone · rcloneApr 22, 2026
- CVE-2026-4117637Monitor
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
CriticalCVSS 9.2Proof of conceptEPSS 3%rclone · rcloneApr 22, 2026
- CVE-2026-5973335Monitor
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
HighCVSS 8.8No exploitEPSS 1%rclone · rcloneJul 14, 2026
- CVE-2026-5457235Monitor
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
HighCVSS 8.8No exploitEPSS 0%rclone · rcloneJul 14, 2026
- CVE-2020-2892430Monitor
An issue was discovered in Rclone before 1.53.3.
HighCVSS 7.5No exploitEPSS 1%rclone · rcloneNov 19, 2020
- CVE-2018-1290730Monitor
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmiss
HighCVSS 7.5No exploitEPSS 1%rclone · rcloneJun 27, 2018
- CVE-2026-8801729Monitor
rclone: FTP cross-session auth-proxy backend confusion
HighCVSS 7.3No exploitEPSS 0%rclone · rcloneSep 10, 2026
- CVE-2026-8801628Monitor
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
HighCVSS 7.1No exploitEPSS 0%rclone · rcloneSep 10, 2026
- CVE-2026-8801425Monitor
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
MediumCVSS 6.3No exploitEPSS 0%rclone · rcloneSep 10, 2026
- CVE-2026-8801521Monitor
rclone local: crafted Range request against a translated symlink panics (DoS)
MediumCVSS 5.3No exploitEPSS 1%rclone · rcloneSep 10, 2026
- CVE-2026-8801321Monitor
rclone: http backend forwards custom/auth headers to a different host on redirect
MediumCVSS 5.3No exploitEPSS 0%rclone · rcloneSep 10, 2026
- CVE-2026-5973220Monitor
rclone archive extract allows S3 destination prefix escape via crafted archive paths
MediumCVSS 5.0No exploitEPSS 0%rclone · rcloneJul 14, 2026