CVE-2026-79779

Description

A flaw was found in rclone. The application fails to reject transport downgrades during redirect handling, which allows Basic authorization and Cookie headers to be replayed over plaintext HTTP following HTTPS-to-HTTP redirects on the same host. An on-path attacker can observe this plaintext communication, capture, and reuse credentials, leading to unauthorized WebDAV operations with the compromised account's permissions.

Statement

This Moderate impact flaw in rclone allows an on-path attacker to capture credentials by exploiting improper handling of HTTPS-to-HTTP redirects on the same host. This occurs when rclone fails to reject transport downgrades, leading to the replay of Basic authorization and Cookie headers over plaintext HTTP. Exploitation requires the attacker to be positioned on the network path between the client and the server.

Mitigation

Until packages are updated, avoid using rclone WebDAV remotes against servers or gateways that issue HTTPS-to-HTTP redirects. Prefer remotes that remain on HTTPS for the full request path, and do not send Basic authentication or session cookies through intermediaries that can downgrade the TLS connection.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.3N/A5.3
Attack VectorAdjacent NetworkN/AAdjacent Network
Attack ComplexityHighN/AHigh
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactNoneN/ANone
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

cve.org: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

Frequently Asked Questions

Want to get errata notifications? Sign up here.