Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise. | |
| Title | rclone before 1.74.4 Privilege Escalation via setuid Metadata | |
| First Time appeared |
Rclone
Rclone rclone |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rclone
Rclone rclone |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T16:11:49.885Z
Reserved: 2026-08-25T14:32:37.762Z
Link: CVE-2026-79783
No data.
Status : Received
Published: 2026-08-25T16:17:30.383
Modified: 2026-08-25T16:17:30.383
Link: CVE-2026-79783
No data.
OpenCVE Enrichment
No data.