THREAT OPS › Threat News › [NVD] CVE-2026-49980 (CRITICAL 9.8) — Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from
[NVD] CVE-2026-49980 (CRITICAL 9.8) — Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from
CVE-2026-49980 CVSS: 9.8 CRITICAL Published: 2026-06-24T19:17:11.597
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initializati
Indicators of compromise
- CVE-2026-49980cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49980