Bug 2492478 (CVE-2026-49980)

Summary: CVE-2026-49980 github.com/rclone/rclone: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, cmah, dymurray, eaguilar, ebaron, gparvin, jmatsuok, jmatthew, jolong, jtolenti, pahickey, pjindal, rhaigner, rjohnson, whayutin
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Rclone, a command-line program for cloud storage synchronization. When the `rcd --rc-serve` option is enabled, an unauthenticated remote attacker can send specially crafted GET or HEAD requests to execute arbitrary commands as the Rclone process user. This vulnerability allows for remote code execution, potentially compromising the system where Rclone is running.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2492920, 2492921, 2492923, 2492924, 2492919, 2492922, 2492926    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-24 19:01:50 UTC
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.

Comment 3 Yadnyawalk Tale 2026-08-07 11:29:45 UTC
CVSS difference Justification
===============================
We believe AC:L should be adjusted to AC:H, as exploitation requires a non-default configuration (rclone rcd --rc-serve) with an unauthenticated, externally reachable RC endpoint. Since these prerequisites are not present in the default configuration, successful exploitation depends on specific deployment conditions, increasing the attack complexity. As a result, we believe the appropriate CVSS score is 8.1 and not 9.8.

Additional Pre-conditions can be referred here in this advisory: https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv