CVE-2026-41176
rclone rclone, OpenShift API for Data Protection, Red Hat Advanced Cluster Management for Kubernetes 2
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitiv...
- CVSS
- 9.2
- EPSS
- 32.7% 98.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.23