Description
rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects to access protected S3 objects.
Published: 2026-08-25
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Exposure of credentials during S3 redirects
Action: Immediate Upgrade
AI Analysis

Impact

rclone versions before 1.75.0 do not sanitize IBM IAM bearer tokens and SSE-C encryption keys when handling S3 redirect callbacks, which can preserve those secrets across scheme changes or host modifications. This flaw can expose authenticating tokens that grant access to protected S3 objects.

Affected Systems

The vulnerability affects all rclone rclone releases prior to 1.75.0 that use IBM Cloud Object Storage with redirect callbacks. Users employing S3 redirect features with IBM IAM tokens or SSE-C keys are at risk.

Risk and Exploitability

The flaw carries a CVSS score of 6.0, indicating a moderate impact. With an EPSS score of 0.00095 (less than 1%), the lack of an entry in the CISA KEV catalog suggests limited documented exploitation. An attacker who can observe traffic from a trusted endpoint—for example, during same-host HTTPS-to-HTTP downgrades or cross-origin redirect flows—can capture reusable IBM IAM tokens or SSE-C keys, gaining unauthorized access to S3 data. The primary attack vector is network eavesdropping during redirect callbacks.

Generated by OpenCVE AI on August 31, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade rclone to version 1.75.0 or newer.
  • Configure redirect callbacks to enforce HTTPS and limit redirections to trusted hosts.
  • Monitor network traffic for unexpected scheme or host changes during S3 redirect operations.

Generated by OpenCVE AI on August 31, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects to access protected S3 objects.
Title rclone before v1.75.0 Credential Exposure via S3 Redirect
First Time appeared Rclone
Rclone rclone
Weaknesses CWE-200
CPEs cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
Vendors & Products Rclone
Rclone rclone
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-25T16:07:21.266Z

Reserved: 2026-08-25T14:32:37.762Z

Link: CVE-2026-79780

cve-icon Vulnrichment

Updated: 2026-08-25T16:07:18.244Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T16:17:29.947

Modified: 2026-09-10T20:46:19.780

Link: CVE-2026-79780

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T15:16:09Z

Links: CVE-2026-79780 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T14:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-201

    Insertion of Sensitive Information Into Sent Data