VULNRABLE / Vulnerability / CVE-2026-88018
CVE-2026-88018
CRITICAL WATCH github.com/rclone/rclone GHSA
Exploit verdict: CVSS 9.5 · critical severity
CVSS Score
9.5
Severity
CRITICAL
EPSS
0%
Source
GHSA
Summary
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
What this means
CVE-2026-88018 is a critical-severity vulnerability affecting github.com/rclone/rclone, rated CVSS 9.5. The EPSS model estimates a 0% probability of exploitation in the next 30 days. Published September 11, 2026.
View full advisory at GHSA →