tag
Webdav
CVE-2026-41179
web
CRITICAL 9.8
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
rclone's built-in Remote Control (rcd) HTTP API exposes an /operations/fsinfo endpoint that accepts an attacker-controlled fs= connection-string parameter used to instantiate a storage backend. When the string selects the WebDAV backend, rclone recognizes an…
Patched
2026-07-05
None assigned as of 2026-07-03
cloud
HIGH
Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
When a Nextcloud user creates a normal federated file share, the sender instance generates a permanent authentication token that is also stored as the federated share's secret; that token is created without an explicit narrow scope, so it defaults to full…
Unverified
2026-07-03