Privilege Escalation Vulnerability in Rclone by Rclone
CVE-2026-79783
2LOW
What is CVE-2026-79783?
Rclone, prior to version 1.74.4, is susceptible to a privilege escalation vulnerability which occurs due to the application failing to properly mask special permission bits when processing source-supplied mode metadata within the local backend. Attackers can exploit this flaw by injecting malicious files that set setuid/setgid bits, resulting in the potential execution of binaries with escalated privileges. If Rclone operates under root permissions, this could enable unauthorized access to system-level commands, while attackers targeting a service account could also gain elevated abilities.
Affected Version(s)
rclone 0 < 1.74.4
rclone 1.74.4
