Skip to content

Known CVE

Rclone RC - Broken Access Control

Rclone >= 1.45.0 and < 1.73.5 contains a broken access control vulnerability caused by unauthenticated access to the RC endpoint `options/set` allowing mutation of global runtime configuration, letting unauthenticated attackers access sensitive administrative functions, exploit requires RC server started without global HTTP authentication.

CVE-2026-41176

Critical2026CVSS 9.2CWE-306

cve2026 · rclone · auth-bypass · rce · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website