Security Advisory

CVE-2026-79776

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-25 15:16:07
Last updated 2026-08-25 17:27:57
Assigner VulnCheck
CVSS score 6.9
State PUBLISHED

Description

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.