Rclone is a command-line file-synchronization and cloud-storage management tool that connects to a broad range of storage backends, and its vulnerability exposure centers on authentication bypass, sensitive-information disclosure, OS command injection, and cryptographic-entropy weaknesses. These patterns reflect the tool's role as a bridge between local systems and remote storage services, where authentication strength, credential handling, and shell-command safety are structural security boundaries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rclone over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41176CRITICAL Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, | Apr 23, 2026 | 9.8 | 67 | NO | YES |
CVE-2026-41179CRITICAL Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoin | Apr 23, 2026 | 9.8 | 53 | NO | YES |
CVE-2026-54572HIGH Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclon | Jul 14, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-59733HIGH Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authoriz | Jul 14, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-49980CRITICAL Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticate | Jun 24, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-59732MEDIUM Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outs | Jul 14, 2026 | 5.0 | 26 | NO | NO |
CVE-2020-28924HIGH An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy t | Nov 19, 2020 | 7.5 | 24 | NO | NO |
CVE-2018-12907HIGH In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, beca | Jun 27, 2018 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rclone.
Media articles that mention a CVE ID that affects a product developed by Rclone — matched by CVE ID, not by vendor name.