CVE-2026-88044 | Rclone up to 1.75.0 FTP/S3 Constructors cmd/serve/ftp/ftp.go AuthProxy improper authentication

SecurityVulns

A vulnerability classified as critical was found in Rclone up to 1.75.0. Affected by this issue is some unknown functionality of the file cmd/serve/ftp/ftp.go of the component FTP/S3 Constructors. The manipulation of the argument AuthProxy results in improper authentication.

This vulnerability is known as CVE-2026-88044. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More