Threats Tagged 'bit-rclone-2026-41176'
View all threats tagged with 'bit-rclone-2026-41176'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bit-rclone-2026-41176'
Click on any threat for detailed analysis and mitigation recommendations
BIT-rclone-2026-41176: Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionCVE-2026-41176 0 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set `rc.NoAuth=true`, which disables the authorization gate for many RC methods registered with `AuthRequired: true` on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue. Join the discussion | GCVE Database | 04/24/2026, 08:51:07 UTC Added: 07/06/2026, 23:04:15 UTC |
Showing 1 to 1 of 1 result