Bug 2500770 (CVE-2026-59733)
| Summary: | CVE-2026-59733 rclone: Rclone: Unauthorized access to private repositories via directory traversal | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Rclone. When using the `rclone serve restic --private-repos` command, an authenticated user can include directory traversal sequences (e.g., `..`) in a request. This allows them to bypass authorization and read, overwrite, or delete another user's private repository on backends that clean path components. This vulnerability can lead to significant information disclosure, data integrity issues, and denial of service for other users' data.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-14 22:05:53 UTC
|