CVE-2026-79780
Description
A flaw was found in rclone. The application fails to properly sanitize IBM IAM bearer tokens and Server-Side Encryption with Customer-Provided Keys (SSE-C) encryption keys during S3 redirect callbacks. This allows credentials to be preserved across scheme or host changes. A remote attacker observing network traffic from a trusted endpoint could capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects, leading to information disclosure and potential unauthorized access to protected S3 objects.
Statement
This Moderate flaw in rclone allows for information disclosure of IBM IAM bearer tokens or SSE-C encryption keys. When rclone interacts with S3 endpoints that issue unsafe redirects, an adjacent network attacker can capture these credentials during HTTPS-to-HTTP downgrades or cross-origin redirects. The impact is constrained by the scope of the captured token and the attacker's access to encrypted objects.
Mitigation
Until packages are updated, avoid using rclone S3 remotes with IBM IAM bearer tokens or SSE-C customer-provided keys against endpoints or gateways that issue cross-scheme or cross-host redirects. Prefer trusted HTTPS endpoints that do not downgrade or redirect secret-bearing requests.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.3 | N/A | 5.3 |
| Attack Vector | Adjacent Network | N/A | Adjacent Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | High | N/A | High |
| Integrity Impact | None | N/A | None |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
cve.org: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Understanding the Weakness (CWE)
Confidentiality
Technical Impact: Read Files or Directories; Read Memory; Read Application Data
Sensitive data may be exposed to attackers.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.