CVE-2026-79783 - CERT CVE
ID CVE-2026-79783
Sažetak rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.
Reference
CVSS
Base: 3.6
Impact: 2.5
Exploitability:1.0
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 25-08-2026 - 17:18
Objavljeno 25-08-2026 - 16:17