This bug was fixed in the package rclone - 1.60.1+dfsg-4ubuntu3.2
---------------
rclone (1.60.1+dfsg-4ubuntu3.2) resolute-security; urgency=medium
* SECURITY UPDATE: unauthenticated remote command execution in rcd
(LP: #2160382)
- d/p/CVE-2026-49980.patch: Disable unauthenticated inline remotes
- CVE-2026-49980
-- Wesley Hershberger <[email protected]> Fri, 10 Jul
2026 15:28:33 -0500
** Changed in: rclone (Ubuntu Resolute)
Status: In Progress => Fix Released
** CVE added: https://cve.org/CVERecord?id=CVE-2026-49980
** Changed in: rclone (Ubuntu Jammy)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160382
Title:
CVE-2026-49980
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/rclone/+bug/2160382/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs