CVE-2026-41176

CRITICAL

CVSS v3.1: 9.8 · EPSS: 0.3453 (98.2 percentile)

EPSS highNetworkNo privilegesNo user interactionMissing AuthenticationVendor advisory ref

Source data as of:

At a glance

Severity
CRITICAL
CVSS
9.8 v3.1 · NVD
EPSS
0.3453 (98.2 percentile) · FIRST.org
CISA KEV
No
Type
Missing Authentication · NVD CWE
Attack conditions (CVSS vector)
NetworkNo privilegesNo user interaction · Source: NVD Vector
Affected vendors
rclone
Published
2026-04-23 · Modified: 2026-06-30

CVSS / EPSS / KEV

CVSS v3.1 9.8 / 10 CRITICAL Source: NVD
CVSS v4.0 9.2 / 10 CRITICAL Source: NVD
EPSS 0.3453 98.2 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.

Record details

CVE ID
CVE-2026-41176
CVSS (v3.1)
9.8 (CRITICAL)
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability subscore
3.9
Impact subscore
5.9
EPSS
0.3453 (98.2 percentile) — 2026-06-30
CISA KEV
No
Weakness (CWE)
CWE-306, CWE-15
Affected vendors
rclone
Affected configurations (CPE)
1
Published
2026-04-23
Modified
2026-06-30
Status
Modified

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.