Database/Control plane, storage & DevOps
rclone (rcd remote control server): An unauthenticated request to the rclone remote-control server instantiates a
Impact
An unauthenticated request to the rclone remote-control server instantiates a backend defined inline in the request, and some backend options run commands. That is unauthenticated arbitrary command execution as whatever user rclone runs as - typically the data-mover service account holding credentials to every storage system it touches.
Who can reach it
Anyone who can reach the rclone rcd HTTP port. Data movers are commonly run on a shared node with the port bound broadly, so a tenant on the same network is enough.
What to do
Upgrade rclone to the fixed release and restart every rcd/serve instance. Treat any exposed instance as compromised and rotate all remote credentials in its config. Bind rcd to loopback, require --rc-user/--rc-pass, and never expose it on a tenant-reachable interface.
References
Related entries
- Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachableCVE-2026-51080 · Proxmox VE (libpve-storage-perl XXE)Critical
- Linux NFS server (nfsd, SECINFO_NO_NAME decode): A truncated SECINFO_NO_NAME operation leaves sin_exp uninitialized andCVE-2026-53398 · Linux NFS server (nfsd, SECINFO_NO_NAME decode)Critical
- Airflow FAB provider: Azure AD login accepted unsigned ID tokens, allowing login as AdminCVE-2026-59243 · Apache Airflow FAB auth manager (Azure AD OAuth ID token validation)Critical
- VMware vCenter (VMware Directory Service authentication bypass): An unauthenticated attacker with network accessCVE-2026-59309 · VMware vCenter (VMware Directory Service authentication bypass)Critical
- VMware vCenter (Syslog server directory traversal to RCE): Directory traversal in the vCenter syslog server lettingCVE-2026-59310 · VMware vCenter (Syslog server directory traversal to RCE)Critical
- Gitea: unauthenticated remote code execution via the diffpatch API installing Git hooksCVE-2026-60004 · Gitea (diffpatch API / Git hook installation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.