CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-41176: Unauthenticated Auth Bypass in rclone RC Servers

June 25, 2026

CVE-2026-41176 allows an unauthenticated attacker to flip rc.NoAuth on rclone RC servers from version 1.45.0 up to 1.73.5 that were started without HTTP auth, potentially exposing cloud credentials.