CVE-2026-79776 UNKNOWN

CVE-2026-79776

Published: 2026-08-25

Description

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…