Critical severity9.8GHSA Advisory· Published Jun 24, 2026· Updated Aug 7, 2026
CVE-2026-49980
CVE-2026-49980
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/rclone/rcloneGo | >= 1.46.0, < 1.74.3 | 1.74.3 |
Affected products
9- osv-coords7 versionspkg:apk/chainguard/telegraf-1.38pkg:apk/chainguard/telegraf-1.39pkg:apk/wolfi/telegraf-1.38pkg:bitnami/rclonepkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/rclone&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/rclone&distro=openSUSE%20Tumbleweed
< 1.38.4-r19+ 6 more
- (no CPE)range: < 1.38.4-r19
- (no CPE)range: < 1.39.2-r3
- (no CPE)range: < 1.38.4-r19
- (no CPE)range: >= 1.46.0, < 1.74.3
- (no CPE)range: < 0.0.20260827T195228-160000.1.1
- (no CPE)range: < 1.74.4-bp160.1.1
- (no CPE)range: < 1.74.3-1.1
Patches
Vulnerability mechanics
References
6- access.redhat.com/security/cve/CVE-2026-49980nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-qw24-gh76-8rvvghsaADVISORY
- github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvvnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-49980ghsaADVISORY
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49980.jsonnvdThird Party AdvisoryWEB
News mentions
1- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026