Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59733

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.

A flaw was found in Rclone. When using the rclone serve restic --private-repos command, an authenticated user can include directory traversal sequences (e.g., ..) in a request. This allows them to bypass authorization and read, overwrite, or delete another user's private repository on backends that clean path components. This vulnerability can lead to significant information disclosure, data integrity issues, and denial of service for other users' data.

Отчет

This Moderate flaw in Rclone's serve restic --private-repos command allows an authenticated attacker to bypass authorization. By using directory traversal sequences in requests, an attacker can access, modify, or delete other users' private repositories. This could lead to unauthorized data access and integrity issues for users of affected Rclone services.

Меры по смягчению последствий

To mitigate this issue, avoid using the rclone serve restic --private-repos command if its functionality is not strictly required. Upgrading to v1.74.4 fixes the issue.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2500770rclone: Rclone: Unauthorized access to private repositories via directory traversal

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
20 дней назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.

CVSS3: 8.8
nvd
20 дней назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.

CVSS3: 8.8
debian
20 дней назад

Rclone is a command-line program to sync files and directories to and ...

suse-cvrf
12 дней назад

Security update for rclone

7.5 High

CVSS3