Path Traversal Vulnerability in Rclone Software by Rclone, Inc.
CVE-2026-93986

2.3LOW

Key Information:

Vendor

Rclone

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-93986?

The vulnerability in Rclone versions prior to 1.75.1 arises from inadequate confinement of names generated from server and third-party directory listings. This oversight allows attackers to exploit crafted object names that include path traversal sequences such as forward slashes and parent directory references. Although local backend protections currently mitigate the risk of unauthorized file writing outside the intended directory, the flaw still exposes systems to potential exploitation and emphasizes the need for an immediate update.

Affected Version(s)

rclone 0 < 1.75.1

rclone 1.75.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut
ncw
.