Database/Control plane, storage & DevOps
rclone (serve restic --private-repos): --private-repos is meant to confine each authenticated user to their own
Impact
--private-repos is meant to confine each authenticated user to their own repository, but a .. in the URL path walks out of it. An authenticated tenant reads, overwrites and deletes other tenants' backup repositories - so the isolation flag you deployed specifically for multi-user backup does not hold.
Who can reach it
Any authenticated user of an rclone serve restic endpoint running with --private-repos.
What to do
Upgrade rclone and restart the serve restic instance. Audit repository contents and object timestamps for cross-user writes. Where possible back the separation with per-user storage credentials or separate buckets instead of trusting the path prefix.
References
Related entries
- Red Hat ACM: ManagedClusterAddOn annotation overrides governance-policy image, giving cluster-admin execCVE-2026-66793 · Red Hat Advanced Cluster Management governance-policy-addon-controllerHigh
- Apache Airflow: Callback deserialization in the scheduler timeout sweep imports Dag-author-chosen modulesCVE-2026-67587 · Apache Airflow Task SDK Callback deserialization (task instance next_kwargs)High
- Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns): A VXLAN tunnel's `changelink()` operates acrossCVE-2026-68432 · Linux VXLAN driver (CAP_NET_ADMIN check on changelink across netns)High
- Jenkins Multijob Plugin: Groovy features skip Script Security, giving job configurers controller RCECVE-2026-70431 · Jenkins Multijob Plugin (Groovy scripting outside Script Security)High
- Jenkins Multijob Plugin: CSRF lets an attacker run code in the Jenkins controller JVMCVE-2026-70432 · Jenkins Multijob Plugin (CSRF on code-executing endpoint)High
- Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): The OCTEON CN10K admin-function mailbox handlerCVE-2026-72045 · Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.