OVERVIEW CVE-2026-41176 is an authentication bypass vulnerability in Rclone, a command-line file synchronization tool for cloud storage. The vulnerability affects Rclone versions 1.45.0 through 1.73.4. The RC endpoint "options/set" is exposed without proper authentication requirements, allowing unauthenticated attackers to modify global runtime configuration parameters on accessible RC servers. SEVERITY This vulnerability has a network-based attack vector with low complexity. An unauthenticated attacker can set the rc.NoAuth parameter to true, which disables authorization checks for numerous RC methods that normally require authentication. This leads to unauthorized access to sensitive administrative functionality, including configuration and operational commands. The FAUCET Risk Score of 53.0/100 indicates moderate risk, though the CVSS score is not yet assigned. The EPSS score of 0.0004 suggests current exploitation probability is very low. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, and it is classified as inactive on the Hot List. No public exploit code or active exploitation has been identified in the threat landscape. The patch is available in Rclone version 1.73.5 and later, and community attention appears limited. Organizations using affected versions should prioritize patching, particularly those operating RC servers with network accessibility.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.45, < 1.73.5CPE matchmatch criteria | cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.