USN-8782-1: Rclone vulnerability
Ubuntu fixed Rclone CVE-2026-49980, where unauthenticated requests to the remote control API can execute arbitrary commands.
Ubuntu Security Notice USN-8782-1 addresses a flaw in which Rclone incorrectly handled unauthenticated requests to its remote control API. An attacker could exploit this issue to execute arbitrary commands with the privileges of the user invoking rclone. The notice provides patched Rclone packages for supported Ubuntu releases, and users are advised to update.
- Flaw tracked as CVE-2026-49980 affects Rclone's remote control API
- Unauthenticated requests could enable arbitrary command execution as the invoking user
- Fixed packages available via Ubuntu security notice USN-8782-1
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-49980 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3. NVD description · AI analysis pending | 9.8 | <1% |
| — |
It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to execute arbitrary commands as the user invoking rclone. (CVE-2026-49980)
This source does not provide full text. Read it at ubuntu.com.