CVE-2026-79779
Description
A flaw was found in rclone. The application fails to reject transport downgrades during redirect handling, which allows Basic authorization and Cookie headers to be replayed over plaintext HTTP following HTTPS-to-HTTP redirects on the same host. An on-path attacker can observe this plaintext communication, capture, and reuse credentials, leading to unauthorized WebDAV operations with the compromised account's permissions.
Statement
This Moderate impact flaw in rclone allows an on-path attacker to capture credentials by exploiting improper handling of HTTPS-to-HTTP redirects on the same host. This occurs when rclone fails to reject transport downgrades, leading to the replay of Basic authorization and Cookie headers over plaintext HTTP. Exploitation requires the attacker to be positioned on the network path between the client and the server.
Mitigation
Until packages are updated, avoid using rclone WebDAV remotes against servers or gateways that issue HTTPS-to-HTTP redirects. Prefer remotes that remain on HTTPS for the full request path, and do not send Basic authentication or session cookies through intermediaries that can downgrade the TLS connection.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.3 | N/A | 5.3 |
| Attack Vector | Adjacent Network | N/A | Adjacent Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | High | N/A | High |
| Integrity Impact | None | N/A | None |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
cve.org: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.