{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49980.json"
      }
    ],
    "title": "github.com/rclone/rclone: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled",
    "tracking": {
      "current_release_date": "2026-08-07T12:15:31+00:00",
      "generator": {
        "date": "2026-08-07T12:15:31+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.12"
        }
      },
      "id": "CVE-2026-49980",
      "initial_release_date": "2026-06-24T17:52:33.024000+00:00",
      "revision_history": [
        {
          "date": "2026-06-24T17:52:33.024000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-07T11:29:46+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-07T12:15:31+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Cryostat 4",
                "product": {
                  "name": "Cryostat 4",
                  "product_id": "cryostat_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:cryostat:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Cryostat 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "OpenShift API for Data Protection",
                "product": {
                  "name": "OpenShift API for Data Protection",
                  "product_id": "openshift_api_for_data_protection",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift_api_data_protection:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "OpenShift API for Data Protection"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Advanced Cluster Management for Kubernetes 2",
                "product": {
                  "name": "Red Hat Advanced Cluster Management for Kubernetes 2",
                  "product_id": "red_hat_advanced_cluster_management_for_kubernetes_2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:acm:2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Advanced Cluster Management for Kubernetes 2"
          },
          {
            "category": "product_version",
            "name": "cryostat/cryostat-storage-rhel9",
            "product": {
              "name": "cryostat/cryostat-storage-rhel9",
              "product_id": "cryostat/cryostat-storage-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/cryostat-storage-rhel9?repository_url=registry.redhat.io/cryostat/cryostat-storage-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "oadp/oadp-mustgather-rhel9",
            "product": {
              "name": "oadp/oadp-mustgather-rhel9",
              "product_id": "oadp/oadp-mustgather-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/oadp-mustgather-rhel9?repository_url=registry.redhat.io/oadp/oadp-mustgather-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "oadp/oadp-velero-restic-restore-helper-rhel9",
            "product": {
              "name": "oadp/oadp-velero-restic-restore-helper-rhel9",
              "product_id": "oadp/oadp-velero-restic-restore-helper-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/oadp-velero-restic-restore-helper-rhel9?repository_url=registry.redhat.io/oadp/oadp-velero-restic-restore-helper-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "oadp/oadp-velero-rhel9",
            "product": {
              "name": "oadp/oadp-velero-rhel9",
              "product_id": "oadp/oadp-velero-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/oadp-velero-rhel9?repository_url=registry.redhat.io/oadp/oadp-velero-rhel9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhacm2/volsync-operator-bundle",
            "product": {
              "name": "rhacm2/volsync-operator-bundle",
              "product_id": "rhacm2/volsync-operator-bundle",
              "product_identification_helper": {
                "purl": "pkg:oci/volsync-operator-bundle?repository_url=registry.redhat.io/rhacm2/volsync-operator-bundle"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhacm2/volsync-rhel9",
            "product": {
              "name": "rhacm2/volsync-rhel9",
              "product_id": "rhacm2/volsync-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/volsync-rhel9?repository_url=registry.redhat.io/rhacm2/volsync-rhel9"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "cryostat/cryostat-storage-rhel9 as a component of Cryostat 4",
          "product_id": "cryostat_4:cryostat/cryostat-storage-rhel9"
        },
        "product_reference": "cryostat/cryostat-storage-rhel9",
        "relates_to_product_reference": "cryostat_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "oadp/oadp-mustgather-rhel9 as a component of OpenShift API for Data Protection",
          "product_id": "openshift_api_for_data_protection:oadp/oadp-mustgather-rhel9"
        },
        "product_reference": "oadp/oadp-mustgather-rhel9",
        "relates_to_product_reference": "openshift_api_for_data_protection"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "oadp/oadp-velero-restic-restore-helper-rhel9 as a component of OpenShift API for Data Protection",
          "product_id": "openshift_api_for_data_protection:oadp/oadp-velero-restic-restore-helper-rhel9"
        },
        "product_reference": "oadp/oadp-velero-restic-restore-helper-rhel9",
        "relates_to_product_reference": "openshift_api_for_data_protection"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "oadp/oadp-velero-rhel9 as a component of OpenShift API for Data Protection",
          "product_id": "openshift_api_for_data_protection:oadp/oadp-velero-rhel9"
        },
        "product_reference": "oadp/oadp-velero-rhel9",
        "relates_to_product_reference": "openshift_api_for_data_protection"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/volsync-operator-bundle as a component of Red Hat Advanced Cluster Management for Kubernetes 2",
          "product_id": "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-operator-bundle"
        },
        "product_reference": "rhacm2/volsync-operator-bundle",
        "relates_to_product_reference": "red_hat_advanced_cluster_management_for_kubernetes_2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/volsync-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2",
          "product_id": "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-rhel9"
        },
        "product_reference": "rhacm2/volsync-rhel9",
        "relates_to_product_reference": "red_hat_advanced_cluster_management_for_kubernetes_2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-49980",
      "cwe": {
        "id": "CWE-78",
        "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"
      },
      "discovery_date": "2026-06-24T19:01:27.946042+00:00",
      "flags": [
        {
          "label": "component_not_present",
          "product_ids": [
            "cryostat_4:cryostat/cryostat-storage-rhel9"
          ]
        },
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift_api_for_data_protection:oadp/oadp-mustgather-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-restic-restore-helper-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-rhel9",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-operator-bundle",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2492478"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in Rclone, a command-line program for cloud storage synchronization. When the `rcd --rc-serve` option is enabled, an unauthenticated remote attacker can send specially crafted GET or HEAD requests to execute arbitrary commands as the Rclone process user. This vulnerability allows for remote code execution, potentially compromising the system where Rclone is running.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "github.com/rclone/rclone: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "OpenShift API for Data Protection (OADP) and Red Hat Advanced Cluster Management for Kubernetes (RHACM) do not run rclone rcd --rc-serve with an unauthenticated RC listener. OADP relies on Restic (rclone serve restic --stdio) and Kopia (WebDAV serve with RC authentication), while RHACM VolSync uses rclone sync/copy or only compile-time dependencies.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "cryostat_4:cryostat/cryostat-storage-rhel9",
          "openshift_api_for_data_protection:oadp/oadp-mustgather-rhel9",
          "openshift_api_for_data_protection:oadp/oadp-velero-restic-restore-helper-rhel9",
          "openshift_api_for_data_protection:oadp/oadp-velero-rhel9",
          "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-operator-bundle",
          "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-49980"
        },
        {
          "category": "external",
          "summary": "RHBZ#2492478",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2492478"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-49980",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-49980"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-49980",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49980"
        },
        {
          "category": "external",
          "summary": "https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv",
          "url": "https://github.com/rclone/rclone/security/advisories/GHSA-qw24-gh76-8rvv"
        }
      ],
      "release_date": "2026-06-24T17:52:33.024000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "cryostat_4:cryostat/cryostat-storage-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-mustgather-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-restic-restore-helper-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-rhel9",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-operator-bundle",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "cryostat_4:cryostat/cryostat-storage-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-mustgather-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-restic-restore-helper-rhel9",
            "openshift_api_for_data_protection:oadp/oadp-velero-rhel9",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-operator-bundle",
            "red_hat_advanced_cluster_management_for_kubernetes_2:rhacm2/volsync-rhel9"
          ]
        }
      ],
      "title": "github.com/rclone/rclone: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled"
    }
  ]
}