CPE
critical
advisory
SigV4 Authentication Bypass in rclone serve s3
4 TTPs 1 CVEA critical authentication bypass vulnerability in rclone's S3 serving mode allows unauthenticated attackers to spoof identity via forged SigV4 signatures when '--auth-proxy' is used without '--auth-key'.
rclone +3
authentication-bypass
s3
cve-2026-88018
vulnerability
ftp
session-hijacking
authentication
cve-2026-88017
+2
4t
1c
high
advisory
Authorization Bypass in rclone serve restic --private-repos
1 rule 5 TTPs 3 CVEsAn authorization bypass vulnerability in rclone's restic server allows authenticated users to access and manipulate repositories of other users via path traversal, impacting multi-tenant environments using backend storage that canonicalizes path segments.
rclone +1
1r
5t
3c
updated