What is CVE-2026-71309?
The CVE-2026-71309 vulnerability was discovered in rclone's "serve restic" feature, affecting versions 1.40.0 through 1.75.0. It fails to properly reject URL paths starting with "../", which could allow unauthorized file access. Users are advised to update rclone to the latest version.
Azərbaycanca: CVE-2026-71309 zəifliyi rclone-un "serve restic" funksiyasında aşkarlanıb və 1.40.0-dan 1.75.0-a qədər versiyalara təsir edir. Bu, URL-də "../" ilə başlayan yolun düzgün rədd edilməməsi səbəbindən icazəsiz fayl əldə etməyə imkan verir. İstifadəçilərə rclone-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which feature of rclone was the CVE-2026-71309 vulnerability discovered?
The CVE-2026-71309 vulnerability was discovered in rclone's "serve restic" feature.
Which versions of rclone are affected by CVE-2026-71309?
CVE-2026-71309 affects rclone versions 1.40.0 through 1.75.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.