Database/Control plane, storage & DevOps
rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's auth
Impact
options/set is exposed pre-authentication and can rewrite the running instance's auth settings, so an attacker first turns the remaining protections off and then drives the rest of the rc API - up to command execution. One unauthenticated call converts a partly-protected data mover into a fully open one.
Who can reach it
Any host with network reach to the rclone rc endpoint.
What to do
Upgrade rclone and restart every rc/serve process. Rotate remote credentials for exposed instances. Bind the rc listener to loopback and put it behind an authenticating proxy rather than relying on rclone's own flags alone.
References
Related entries
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCVE-2026-41179 · rclone (rc API, operations/fsinfo)Critical
- Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requestsCVE-2026-88880 · Renovate (GitLab pagination, HTTP Link header host validation)Critical
- Renovate: unvalidated GitHub Link header sends host credentials to an attacker-controlled serverCVE-2026-88881 · Renovate (GitHub pagination, HTTP Link header host validation)Critical
- Renovate: NuGet datasource follows cross-origin Link pagination and leaks registry credentialsCVE-2026-88882 · Renovate (NuGet datasource registry pagination)Critical
- Renovate: Docker datasource follows cross-origin Link pagination and sends registry credentials to the attacker's hostCVE-2026-88887 · Renovate (container/Docker datasource registry pagination)Critical
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.