Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and cmd/serve/s3/server.go incorrectly check the process-global proxy.Opt.AuthProxy value instead. When the global value is empty, the request-local authentication proxy is ignored: FTP falls back to the fixed filesystem with username anonymous and any password, while S3 with AuthKey serves the fixed RC fs rather than the backend selected by the proxy. The dedicated command-line servers that configure the global option are not affected. This issue is fixed in version 1.75.1.
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to local and cloud storage via authentication bypass
Action: Immediate Patch
AI Analysis

Impact

The rclone serve/start RC interface incorrectly-server AuthProxy setting. When no global proxy is set, the per-server authentication proxy is ignored, causing FTP clients to default to anonymous access with any password and S3 clients to serve a fixed RC filesystem rather than the selected backend. This flaw lets an attacker connect to the rclone server and gain unintended read or write privileges, potentially exfiltrating or altering data. The weakness is identified as CWE-863, reflecting inconsistent safeguard implementation.

Affected Systems

The vulnerability affects rclone versions 1.70.0 through 1.75.1. Any installation using the serve/start RC interface, whether via FTP or configuration is left empty. The fix is included in rclone release 1.75.1; earlier releases without the patch remain at risk.

Risk and Exploitability

The CVSS score of 9.1 classifies this as a high severity flaw. EPSS information is not available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker who can reach the rclone server over the network can exploit or S3 serve endpoints, thereby obtaining unauthorized access without proper credentials.

Generated by OpenCVE AI on September 11, 2026 at 00:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rclone to version 1.75.1 or later, which correctly applies the per-server AuthProxy setting.
  • Ensure that the global proxy setting is non‑empty before starting the serve interface, so that the per‑server configuration is honored if an upgrade is the rclone serve interfaces by applying firewall rules or network segmentation so that only trusted hosts can contact the FTP and S3 endpoints.
  • Consider disabling unused serve functionalities (FTP or S3) to reduce the attack surface if the server does not require them.

Generated by OpenCVE AI on September 11, 2026 at 00:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p569-5gjg-9cmj rclone: RC per-server auth-proxy bypass
History

Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Rclone
Rclone rclone
Vendors & Products Rclone
Rclone rclone

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and cmd/serve/s3/server.go incorrectly check the process-global proxy.Opt.AuthProxy value instead. When the global value is empty, the request-local authentication proxy is ignored: FTP falls back to the fixed filesystem with username anonymous and any password, while S3 with AuthKey serves the fixed RC fs rather than the backend selected by the proxy. The dedicated command-line servers that configure the global option are not affected. This issue is fixed in version 1.75.1.
Title rclone: RC per-server auth-proxy bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T17:14:40.559Z

Reserved: 2026-09-09T21:22:45.433Z

Link: CVE-2026-88044

cve-icon Vulnrichment

Updated: 2026-09-10T17:14:35.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T17:17:08.387

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-88044

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:00:13Z

Weaknesses