CVE-2026-88018 is an authentication bypass in rclone versions before 1.75.1 affecting the S3 server mode when an authentication proxy is configured without an authentication key. The authentication middleware accepts a client-selected access-key ID and associates it with an empty S3 secret. The S3 implementation then validates AWS Signature Version 4 requests using that same empty secret, while the authentication-proxy flow supplies the access-key identifier as both the user identity and authentication value without an independent per-identity secret. An unauthenticated attacker can therefore select an arbitrary access-key ID, generate a valid SigV4 signature using an empty secret, and access the backend selected by the authentication proxy for that identity.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Authentication bypass critico nel servizio S3 di Rclone: un attaccante remoto non autenticato può inviare richieste S3 firmate con chiavi arbitrarie per eludere completamente l'autenticazione e accedere alle risorse esposte.
A critical unauthenticated authentication-bypass vulnerability in rclone's S3 server mode when --auth-proxy is used without --auth-key. It enables a remote attacker to select an arbitrary access key, generate a SigV4 signature using an empty secret, and access the backend resolved by the auth-proxy for that identity.
A network-accessible vulnerability affecting Debian Linux 12.0 and 13.0, rated critical by the supplied CVSS v3 vector (9.8), with potential for high impact to confidentiality, integrity, and availability. The provided content does not identify the affected component or technical flaw.
An authentication bypass in rclone's S3 server mode. When rclone serve s3 is configured with --auth-proxy but without --auth-key, it dynamically registers any client-supplied access key ID with an empty secret. Because an empty string is a valid HMAC key, an unauthenticated remote attacker can generate a valid AWS SigV4 request for an arbitrary access key ID and access the backend identity resolved by the authentication proxy.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.