Rclone 1.64.x < 1.75.1 FTP Auth-Proxy Cross-Session Backend Confusion (CVE-2026-88017)

high Nessus Plugin ID 346827

Synopsis

An application installed on the remote host is affected by a cross-session backend confusion vulnerability.

Description

The version of Rclone installed on the remote host is 1.64.x prior to 1.75.1. It is, therefore, affected by a cross-session backend confusion vulnerability:

- The FTP auth-proxy driver stores one obscured password per username in a server-wide map and does not bind the credential or the returned VFS to the authenticated FTP session. If two accepted credentials use the same username but resolve to different proxy backends, the later login overwrites the map entry, and subsequent operations on the first, still-authenticated session are re-authorized with the later session's password and execute against the later session's backend. A low-privileged user holding a valid auth-proxy credential can therefore gain the read, write, and delete authority of another accepted credential sharing the same FTP username. (CVE-2026-88017)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Rclone version 1.75.1 or later.

See Also

https://github.com/rclone/rclone/releases/tag/v1.75.1

http://www.nessus.org/u?1c7de67b

Plugin Details

Severity: High

ID: 346827

File Name: rclone_CVE-2026-88017.nasl

Version: 1.2

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 9/17/2026

Updated: 9/18/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.47

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-88017

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:rclone:rclone

Required KB Items: installed_sw/rclone

Exploit Ease: No known exploits are available

Patch Publication Date: 9/4/2026

Vulnerability Publication Date: 9/10/2026

Reference Information

CVE: CVE-2026-88017