{"id":"CVE-2026-79783","aliases":["GHSA-945v-v9p3-v5xw","GO-2026-6190"],"url":"https://o3.security/vulnerability/CVE-2026-79783","summary":"rclone before 1.74.4 Privilege Escalation via setuid Metadata","details":"rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.","published":"2026-08-25T15:16:11.806Z","modified":"2026-09-12T03:31:01.353395515Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/rclone/rclone","fixedVersion":"1.74.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79783.json"},{"type":"ADVISORY","url":"https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79783"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/rclone-before-privilege-escalation-via-setuid-metadata"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T03:31:01.353395515Z"}}