Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-88044

A flaw in rclone’s serve/start RC interface caused the program to ignore per-server authentication proxy settings for FTP and S3. As a result, FTP connections defaulted to anonymous access and S3 connections served a fixed filesystem instead of the intended backend. The bug was fixed in rclone version 1.75.1.

publishedSep 10, 2026
last modifiedSep 10, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
41th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 10, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

rclone versions 1.70.0 through 1.75.1, used by users who run the serve/start RC interface with per-server proxy authentication settings.

02

Real-world impact

An attacker could exploit the flaw to bypass authentication, gaining anonymous read or write access to FTP servers or to the fixed rclone filesystem via S3, potentially exposing or altering sensitive data.

03

Why this severity

The CVSS score of 9.1 reflects a network-based attack that requires no user interaction, no privileges, and provides full confidentiality and integrity compromise. The low attack complexity and lack of required privileges make it highly exploitable.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade rclone to version 1.75.1 or later.
  2. 02Restart any rclone services to apply the new version.

NVD-referenced vendor advisory

05

Timeline

  1. Sep 10, 2026 · 3d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Sep 10, 2026 · 3d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →