THREAT OPS › Threat News › [GHSA] GHSA-fqj9-69pf-6pjg (high) — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
[GHSA] GHSA-fqj9-69pf-6pjg (high) — rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
GHSA-fqj9-69pf-6pjg Severity: high CVE: CVE-2026-59733
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
## Summary
`rclone serve restic --private-repos` exists to let one rclone instance host many users' restic backup repositories behind HTTP Basic auth while keeping each user confine
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-59733cve
Original source: https://github.com/advisories/GHSA-fqj9-69pf-6pjg