CVE-2026-88018
CVE-2026-88018 is a critical-severity vulnerability in Rclone with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 1% (42nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Rclone
- Published:
- Last modified:
Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes the access key identifier as both the user and authentication value to the proxy without an independent per-identity secret. An unauthenticated network attacker can therefore choose an arbitrary access key, sign with an empty secret, and reach whatever backend the auth-proxy script resolves for that identity. This issue is fixed in version 1.75.1.
Frequently asked questions
- What is CVE-2026-88018?
- rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes the access key identifier as both the user and authentication value to the proxy without an independent per-identity secret. An unauthenticated network attacker can therefore choose an arbitrary access key, sign with an empty secret, and reach whatever backend the auth-proxy script resolves for that identity. This issue is fixed in version 1.75.1.
- How severe is CVE-2026-88018?
- CVE-2026-88018 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-88018 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (42nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-88018?
- CVE-2026-88018 affects Rclone. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-88018?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-88018 published?
- CVE-2026-88018 was published on 2026-09-10 and last updated on 2026-09-14.
References
- https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd
- https://github.com/rclone/rclone/releases/tag/v1.75.1
- https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c
Affected products (1)
- cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*
More vulnerabilities in Rclone
- CVE-2026-49980 — Critical (CVSS 9.8): Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From…
- CVE-2026-41179 — Critical (CVSS 9.8): Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting…
- CVE-2026-41176 — Critical (CVSS 9.8): Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC…
- CVE-2026-59733 — High (CVSS 8.8): Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to…
- CVE-2026-54572 — High (CVSS 7.5): Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to…
- CVE-2020-28924 — High (CVSS 7.5): An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password…
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →