Bug 2531542 (CVE-2026-88018)
| Summary: | CVE-2026-88018 rclone: rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rclone. When the `rclone serve s3` command is configured with `--auth-proxy` but without `--auth-key`, an unauthenticated network attacker can bypass the SigV4 signature verification process. This allows the attacker to use an arbitrary access key and sign requests with an empty secret, leading to unauthorized access to the backend storage resolved by the authentication proxy script. This vulnerability results in a complete authentication bypass.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2537399, 2537401 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-10 16:14:06 UTC
|