CVE-2026-79776
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Aug 25, 2026
Vendor
unknown
Description
rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.