ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 19 sources: “Ubuntu roundup (2026-09-16 to 2026-09-18): ten USNs fix 16 CVEs, including Rclone unauthenticated command execution and Arm kernel TLB race” — merged summary and timeline →

USN-8782-1: Rclone vulnerability

mediumAdvisoryimportance 35CVE-2026-49980
AI summary · glm-5.3-flash

Ubuntu fixed Rclone CVE-2026-49980, where unauthenticated requests to the remote control API can execute arbitrary commands.

Ubuntu Security Notice USN-8782-1 addresses a flaw in which Rclone incorrectly handled unauthenticated requests to its remote control API. An attacker could exploit this issue to execute arbitrary commands with the privileges of the user invoking rclone. The notice provides patched Rclone packages for supported Ubuntu releases, and users are advised to update.

  • Flaw tracked as CVE-2026-49980 affects Rclone's remote control API
  • Unauthenticated requests could enable arbitrary command execution as the invoking user
  • Fixed packages available via Ubuntu security notice USN-8782-1

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-49980
Rclone is a command-line program to sync files and directories to and from different cloud storage providers.

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.

NVD description · AI analysis pending
9.8<1%
  • rclone rclone
Full article

It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to execute arbitrary commands as the user invoking rclone. (CVE-2026-49980)

This source does not provide full text. Read it at ubuntu.com.