CVE-2026-79783: Rclone

Low severity, CVSS 3.6. EPSS: 0.2% chance of exploitation in the next 30 days.

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

Affected products

  • Rclone Rclone: before 1.74.4 (fixed in 1.74.4)

Published 2026-08-25. Last modified 2026-09-10.