Junglewise Threat Intelligence

CVE-2026-79776: rclone pprof authentication bypass in RC server

CVE-2026-79776 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Rclone. Vendors: Rclone.

Executive brief

rclone is a popular open-source tool for syncing files with cloud storage and managing remote connections. A flaw in versions before 1.75.0 allows unauthenticated attackers on the network to access debugging endpoints that expose sensitive information, including backend storage credentials and full process arguments. This could enable attackers to compromise cloud storage accounts without requiring valid credentials.

Technical details

The pprof debug handler is mounted as a separate router route (line 130 in rcserver.go) on the RC server, bypassing the authentication check that lives inside the main s.handler (line 281). This allows unauthenticated access to /debug/pprof/cmdline and related endpoints over the network. The /cmdline endpoint discloses the full process argv, which often contains backend credentials (e.g., S3 access keys) passed via command-line flags or configuration. No authentication or user interaction is required; an attacker with network access to the RC server can immediately retrieve credentials. The vulnerability is fixed in rclone 1.75.0 by moving the authentication check to middleware on the router level.

Affected products

  • rclone rclone before 1.75.0

Timeline

  • 2026-07-31: disclosed
  • 2026-08-25: advisory
  • 2026-08-25: patched: Fixed in rclone 1.75.0

References

Related threats