UBUNTU-CVE-2026-41176

Source
https://ubuntu.com/security/CVE-2026-41176
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-41176
Upstream
  • CVE-2026-41176
Downstream
Related
Published
2026-04-23T00:16:00Z
Modified
2026-05-25T10:45:07.348382674Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint options/set is exposed without AuthRequired: true, but it can mutate global runtime configuration, including the RC option block itself. Starting in version 1.45.0 and prior to version 1.73.5, an unauthenticated attacker can set rc.NoAuth=true, which disables the authorization gate for many RC methods registered with AuthRequired: true on reachable RC servers that are started without global HTTP authentication. This can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods. Version 1.73.5 patches the issue.

References

Affected packages

Ubuntu:Pro:20.04:LTS / rclone

Package

Name
rclone
Purl
pkg:deb/ubuntu/rclone?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.50.2-2ubuntu0.2+esm1

Affected versions

1.*
1.47.0+ex1-6
1.47.0+ex1-7
1.49.5-2
1.49.5-3
1.50.2-2
1.50.2-2ubuntu0.1
1.50.2-2ubuntu0.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "golang-github-rclone-rclone-dev",
            "binary_version": "1.50.2-2ubuntu0.2+esm1"
        },
        {
            "binary_name": "rclone",
            "binary_version": "1.50.2-2ubuntu0.2+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json"

Ubuntu:22.04:LTS / rclone

Package

Name
rclone
Purl
pkg:deb/ubuntu/rclone?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.53.3-4ubuntu1.22.04.4

Affected versions

1.*
1.53.3-1
1.53.3-2
1.53.3-4
1.53.3-4ubuntu1
1.53.3-4ubuntu1.22.04.1
1.53.3-4ubuntu1.22.04.2
1.53.3-4ubuntu1.22.04.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "golang-github-rclone-rclone-dev",
            "binary_version": "1.53.3-4ubuntu1.22.04.4"
        },
        {
            "binary_name": "rclone",
            "binary_version": "1.53.3-4ubuntu1.22.04.4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json"

Ubuntu:24.04:LTS / rclone

Package

Name
rclone
Purl
pkg:deb/ubuntu/rclone?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.60.1+dfsg-3ubuntu0.24.04.5

Affected versions

1.*
1.60.1+dfsg-2build1
1.60.1+dfsg-3
1.60.1+dfsg-3ubuntu0.24.04.1
1.60.1+dfsg-3ubuntu0.24.04.2
1.60.1+dfsg-3ubuntu0.24.04.3
1.60.1+dfsg-3ubuntu0.24.04.4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "golang-github-rclone-rclone-dev",
            "binary_version": "1.60.1+dfsg-3ubuntu0.24.04.5"
        },
        {
            "binary_name": "rclone",
            "binary_version": "1.60.1+dfsg-3ubuntu0.24.04.5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json"

Ubuntu:25.10 / rclone

Package

Name
rclone
Purl
pkg:deb/ubuntu/rclone?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.60.1+dfsg-4ubuntu2.1

Affected versions

1.*
1.60.1+dfsg-4
1.60.1+dfsg-4ubuntu1
1.60.1+dfsg-4ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "golang-github-rclone-rclone-dev",
            "binary_version": "1.60.1+dfsg-4ubuntu2.1"
        },
        {
            "binary_name": "rclone",
            "binary_version": "1.60.1+dfsg-4ubuntu2.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json"

Ubuntu:26.04:LTS / rclone

Package

Name
rclone
Purl
pkg:deb/ubuntu/rclone?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.60.1+dfsg-4ubuntu3.1

Affected versions

1.*
1.60.1+dfsg-4ubuntu2
1.60.1+dfsg-4ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "golang-github-rclone-rclone-dev",
            "binary_version": "1.60.1+dfsg-4ubuntu3.1"
        },
        {
            "binary_name": "rclone",
            "binary_version": "1.60.1+dfsg-4ubuntu3.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41176.json"