USN-8782-1: Rclone vulnerability
Ubuntu fixed Rclone CVE-2026-49980, where unauthenticated requests to the remote control API can execute arbitrary commands.
Ubuntu Security Notice USN-8782-1 addresses a flaw in which Rclone incorrectly handled unauthenticated requests to its remote control API. An attacker could exploit this issue to execute arbitrary commands with the privileges of the user invoking rclone. The notice provides patched Rclone packages for supported Ubuntu releases, and users are advised to update.
35