CVE-2026-79779 MEDIUM

CVE-2026-79779: rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect

Vendor Rclone
Product rclone
Weakness CWE-319 · Cleartext transmission
Published August 25, 2026
Last update August 27, 2026

CVSS base score

6.0/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and reuse credentials to perform WebDAV operations with the compromised account's permissions.

Key dates

02Disclosure timeline

August 25, 2026 CVE published
August 27, 2026 Record updated