Symlink Vulnerability in Rclone Command-Line Tool
CVE-2026-88016

7.1HIGH

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88016?

Rclone, a command-line tool designed for syncing files and directories with various cloud storage providers, has a vulnerability related to symlink handling in versions before 1.75.1. When utilizing the --links option, an attacker can manipulate a .rclonelink object to create a symlink in the destination. This allows the attacker to manipulate file or directory metadata, including ownership and permissions, thereby bypassing security measures like os.Root confinement. The exploit permits unauthorized control over files outside the intended destination, making it critical for users to upgrade to version 1.75.1 or above for protection against this vulnerability.

Affected Version(s)

rclone < 1.75.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.