CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-79783

lowCVSS 3.6covered by 1 sourcefirst seen 2026-08-25
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

⚡ Watch CVE-2026-79783

Get an email if CVE-2026-79783 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-79783

CVE.org record

Embed the live status

CVE-2026-79783 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-79783 status](https://www.csirts.com/badge/CVE-2026-79783)](https://www.csirts.com/cve/CVE-2026-79783)