Impact
The rclone serve/start RC interface incorrectly-server AuthProxy setting. When no global proxy is set, the per-server authentication proxy is ignored, causing FTP clients to default to anonymous access with any password and S3 clients to serve a fixed RC filesystem rather than the selected backend. This flaw lets an attacker connect to the rclone server and gain unintended read or write privileges, potentially exfiltrating or altering data. The weakness is identified as CWE-863, reflecting inconsistent safeguard implementation.
Affected Systems
The vulnerability affects rclone versions 1.70.0 through 1.75.1. Any installation using the serve/start RC interface, whether via FTP or configuration is left empty. The fix is included in rclone release 1.75.1; earlier releases without the patch remain at risk.
Risk and Exploitability
The CVSS score of 9.1 classifies this as a high severity flaw. EPSS information is not available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker who can reach the rclone server over the network can exploit or S3 serve endpoints, thereby obtaining unauthorized access without proper credentials.
OpenCVE Enrichment
Github GHSA