Bug 2492478 (CVE-2026-49980)
| Summary: | CVE-2026-49980 github.com/rclone/rclone: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | aazores, cmah, dymurray, eaguilar, ebaron, gparvin, jmatsuok, jmatthew, jolong, jtolenti, pahickey, pjindal, rhaigner, rjohnson, whayutin |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Rclone, a command-line program for cloud storage synchronization. When the `rcd --rc-serve` option is enabled, an unauthenticated remote attacker can send specially crafted GET or HEAD requests to execute arbitrary commands as the Rclone process user. This vulnerability allows for remote code execution, potentially compromising the system where Rclone is running.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2492920, 2492921, 2492923, 2492924, 2492919, 2492922, 2492926 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-24 19:01:50 UTC
CVSS difference Justification =============================== We believe AC:L should be adjusted to AC:H, as exploitation requires a non-default configuration (rclone rcd --rc-serve) with an unauthenticated, externally reachable RC endpoint. Since these prerequisites are not present in the default configuration, successful exploitation depends on specific deployment conditions, increasing the attack complexity. As a result, we believe the appropriate CVSS score is 8.1 and not 9.8. Additional Pre-conditions can be referred here in this advisory: https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv |