logo

Critical Rclone Command Execution Bug Threatens Cloud Environments

ID: 3033add3-cb55-5c63-a13f-075404774367

STIX ID: report--3033add3-cb55-5c63-a13f-075404774367

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Do Son

...
...

**Executive Summary:** Security researchers disclosed CVE-2026-49980, a critical unauthenticated remote command-execution vulnerability (CVSS 9.8) in rclone's remote control daemon affecting versions 1.55.0–1.74.2; attackers can exploit crafted GET/HEAD paths and browser-initiated loopback requests to run commands as the service user, so administrators should upgrade to 1.74.3 or higher, enforce HTTP authentication, or disable file serving immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.