Arbitrary File Overwrite in rclone from 1.72.0 to 1.75.1
CVE-2026-88014

6.3MEDIUM

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88014?

The rclone command-line program, used for syncing files with various cloud storage providers, has a directory traversal vulnerability between versions 1.72.0 and 1.75.1. Specifically, the archive ZIP backend method incorrectly processes file names from untrusted central directories, allowing potential writes outside designated directories. This flaw arises when path cleaning operations fail to enforce proper boundaries, which can lead to unauthorized access to file systems. Users are strongly advised to upgrade to version 1.75.1 or later to mitigate this risk.

Affected Version(s)

rclone >= 1.72.0, < 1.75.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.