Bug 2531540 (CVE-2026-88017)
| Summary: | CVE-2026-88017 rclone: rclone: FTP authentication flaw allows unauthorized data access | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rclone, a command-line program for syncing files to cloud storage providers. The FTP authentication proxy driver improperly handles user credentials across sessions. If two users share the same username but are linked to different storage backends, a later login can overwrite the authentication for an active session. This allows the first session to perform unauthorized data operations, including reading, creating, or deleting files, using the second user's permissions.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2536988, 2536989 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-10 16:09:00 UTC
|