CVE-2026-79783

EUVD-2026-65541
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
3.6 LOW
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.42%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
rclonerclone
𝑥
< 1.74.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
rclone
bookworm
postponed
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rclone
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
rclone
Amazon Linux 2023
0:1.75.1-1.amzn2023
fixed
rclone-debuginfo
Amazon Linux 2023
0:1.75.1-1.amzn2023
fixed
rclone-debugsource
Amazon Linux 2023
0:1.75.1-1.amzn2023
fixed