Privilege Escalation Vulnerability in Rclone by Rclone
CVE-2026-79783

2LOW

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79783?

Rclone, prior to version 1.74.4, is susceptible to a privilege escalation vulnerability which occurs due to the application failing to properly mask special permission bits when processing source-supplied mode metadata within the local backend. Attackers can exploit this flaw by injecting malicious files that set setuid/setgid bits, resulting in the potential execution of binaries with escalated privileges. If Rclone operates under root permissions, this could enable unauthorized access to system-level commands, while attackers targeting a service account could also gain elevated abilities.

Affected Version(s)

rclone 0 < 1.74.4

rclone 1.74.4

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vnth4nhnt
ncw
.