# CVE-2026-79777

## Summary

- **CVE ID:** CVE-2026-79777
- **Severity:** MEDIUM
- **CVSS Score:** 5.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-209
- **Published:** Aug 25, 2026
- **Last Modified:** Aug 28, 2026

## Description

rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

## Affected Products

- rclone — rclone (0)
- rclone — rclone (1.75.0)

## References

- [CNA](https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv)
- [CNA](https://www.vulncheck.com/advisories/rclone-before-information-disclosure-via-rc-api)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 14.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._