Missing Authentication for Critical Function Affecting github.com/rclone/rclone/fs/rc/rcserver package, versions >=1.45 <1.73.5


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
32.72% (99th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authentication for Critical Function vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMRCLONERCLONEFSRCRCSERVER-16191585
  • published24 Apr 2026
  • disclosed23 Apr 2026
  • credit0wnerDied

Introduced: 23 Apr 2026

CVE-2026-41176  (opens in a new tab)
CWE-306  (opens in a new tab)

How to fix?

Upgrade github.com/rclone/rclone/fs/rc/rcserver to version 1.73.5 or higher.

Overview

Affected versions of this package are vulnerable to Missing Authentication for Critical Function in the options/set endpoint. An attacker can set rc.NoAuth=true and override default AuthRequired: true which can lead to unauthorized access to sensitive administrative functionality, including configuration and operational RC methods.

Note:

This is only exploitable if:

  • remote control API is enabled, either by the --rc flag or by running the rclone rcd server;

  • remote control API must be reachable by the attacker - by default rclone only serves the rc to localhost unless the --rc-addr flag is in use;

  • rc must have been deployed without global RC HTTP authentication - so not using --rc-user/--rc-pass/--rc-htpasswd etc.

CVSS Base Scores

version 4.0
version 3.1