Database/Control plane, storage & DevOps
rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts an
Impact
operations/fsinfo is reachable without authentication and accepts an attacker-defined backend, so a caller can point it at a WebDAV remote whose bearer_token_command runs a shell command. Same practical outcome as the rcd RCE: code execution on the data-mover host and access to every credential in its config.
Who can reach it
Any host that can reach the rclone rc HTTP endpoint.
What to do
Upgrade rclone and restart all rc/serve instances. Rotate the credentials in the rclone config for anything the host could reach. Enforce authentication on the rc endpoint and keep it off shared networks.
References
Related entries
- Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requestsCVE-2026-88880 · Renovate (GitLab pagination, HTTP Link header host validation)Critical
- Renovate: unvalidated GitHub Link header sends host credentials to an attacker-controlled serverCVE-2026-88881 · Renovate (GitHub pagination, HTTP Link header host validation)Critical
- Renovate: NuGet datasource follows cross-origin Link pagination and leaks registry credentialsCVE-2026-88882 · Renovate (NuGet datasource registry pagination)Critical
- Renovate: Docker datasource follows cross-origin Link pagination and sends registry credentials to the attacker's hostCVE-2026-88887 · Renovate (container/Docker datasource registry pagination)Critical
- Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who canCVE-2017-16727 · Moxa NPort W2150A / W2250A wireless device serverCritical
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.