OVERVIEW CVE-2026-41179 is an unauthenticated remote code execution vulnerability in Rclone affecting versions 1.48.0 through 1.73.4. The vulnerability exists in the RC endpoint "operations/fsinfo," which lacks proper authentication requirements and accepts attacker-controlled filesystem input. By leveraging inline backend definitions supported by rc.GetFs(), an attacker can instantiate arbitrary backends, with the WebDAV backend particularly dangerous due to its execution of bearer_token_command during initialization. SEVERITY The vulnerability presents a critical attack profile characterized by network-based exploitation requiring no authentication and minimal complexity. An unauthenticated attacker can achieve local command execution through a single request to any reachable RC deployment lacking global HTTP authentication. The potential impact is severe, enabling arbitrary code execution with the privileges of the Rclone process, potentially compromising file systems and cloud storage access. EXPLOITATION STATUS The vulnerability is currently active on the CISA Known Exploited Vulnerabilities list, indicating active exploitation in the wild. While no specific public exploit code availability is documented in the provided data, the straightforward nature of the vulnerability and its presence on the KEV catalog suggests demonstrated weaponization. The community attention level appears elevated given its FAUCET Risk Score of 52.0/100 and active status. Organizations should prioritize immediate patching to version 1.73.5 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.48.0, < 1.73.5CPE matchmatch criteria | cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.