Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41179

53
FAUCET Score

OVERVIEW CVE-2026-41179 is an unauthenticated remote code execution vulnerability in Rclone affecting versions 1.48.0 through 1.73.4. The vulnerability exists in the RC endpoint "operations/fsinfo," which lacks proper authentication requirements and accepts attacker-controlled filesystem input. By leveraging inline backend definitions supported by rc.GetFs(), an attacker can instantiate arbitrary backends, with the WebDAV backend particularly dangerous due to its execution of bearer_token_command during initialization. SEVERITY The vulnerability presents a critical attack profile characterized by network-based exploitation requiring no authentication and minimal complexity. An unauthenticated attacker can achieve local command execution through a single request to any reachable RC deployment lacking global HTTP authentication. The potential impact is severe, enabling arbitrary code execution with the privileges of the Rclone process, potentially compromising file systems and cloud storage access. EXPLOITATION STATUS The vulnerability is currently active on the CISA Known Exploited Vulnerabilities list, indicating active exploitation in the wild. While no specific public exploit code availability is documented in the provided data, the straightforward nature of the vulnerability and its presence on the KEV catalog suggests demonstrated weaponization. The community attention level appears elevated given its FAUCET Risk Score of 52.0/100 and active status. Organizations should prioritize immediate patching to version 1.73.5 or later.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.48.0, < 1.73.5CPE matchmatch criteria
cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.2CRITICAL

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
8.58%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2026-41179 · Apr 23, 2026
This CVE's current EPSS score of 0.0858 is in the 90th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/rclone/rcloneFixed in: 1.73.5
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-jfwf-28xr-xw6qcritical

RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution

Apr 22, 2026

References

access.redhat.com / security/cve/CVE-2026-41179
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41179.json
github.com / rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/backend/webdav/webdav.go
Product
github.com / rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/fs/operations/rc.go
Product
github.com / rclone/rclone/blob/bf55d5e6d37fd86164a87782191f9e1ffcaafa82/fs/rc/cache.go
Product
github.com / rclone/rclone/commit/2a9e952b38e03a96bf40c9eb6e8e22199865ee3b
github.com / rclone/rclone/releases/tag/v1.73.5
github.com / rclone/rclone/security/advisories/GHSA-jfwf-28xr-xw6q
ExploitVendor Advisory
rclone.org / changelog