Path Traversal Vulnerability in Rclone S3 Service
CVE-2026-79781

6.9MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79781?

The rclone serve s3 feature prior to version 1.74.4 is susceptible to a path traversal vulnerability. This flaw enables an attacker to manipulate S3 object keys using dot-dot segments, such as '../root-secret.txt', to escape the intended bucket namespace. Consequently, this allows unauthorized access to and manipulation of sensitive files located in the root directory of the server. This exploitation poses significant risks to data integrity and confidentiality in the affected environments.

Affected Version(s)

rclone 0 < 1.74.4

rclone 1.74.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dangel165
ncw
.