CVE-2026-88044 is an improper authorization vulnerability in rclone versions 1.70.0 through versions before 1.75.1. Dynamically created FTP and S3 servers launched through the Remote Control serve/start interface validate the process-global AuthProxy configuration instead of the request-scoped per-server AuthProxy setting. If the global setting is empty, the requested authentication proxy is ignored. FTP falls back to a fixed filesystem with anonymous authentication, while S3 instances using AuthKey can serve the fixed RC filesystem rather than the backend selected by the authentication proxy. Dedicated command-line servers configured with the global AuthProxy option are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Authentication bypass critico in Rclone per servizi FTP e S3 avviati tramite Remote Control. Un attaccante remoto non autenticato può indurre il fallback a modalità meno restrittive, aggirare i controlli configurati e leggere, scrivere o cancellare dati esposti.
A critical authentication-authorization flaw in rclone versions 1.70.0 through 1.75.1 affecting the serve/start RC interface's FTP and S3 server paths. Incorrect use of a process-global authentication-proxy setting can bypass request-local proxy authentication controls and expose an unintended filesystem or backend.
A network-reachable vulnerability tracked as CVE-2026-88044 affecting Debian Linux 12.0 and 13.0. The provided CVSS v3.0 vector indicates no privileges or user interaction are required and high confidentiality and integrity impact, with no availability impact.
An authentication and authorization bypass in rclone RC-started FTP and S3 servers. Versions v1.70.0 through v1.75.0 fail to honor the documented request-local AuthProxy option because server constructors consult a process-global option. FTP can permit anonymous clients to read, write, overwrite, and delete objects in the RC-supplied filesystem. Authenticated S3 clients may be routed to the fixed filesystem rather than the backend selected by the authorization proxy.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.