Description
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.
Published: 2026-09-10
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Unauthorized Ownership and Permission Changes
Action: Patch Immediately
AI Analysis

Impact

rclone versions before 1.75.1 have a flaw whereby a source .rclonelink object can plant a symbolic link in the destination during a sync that uses the --links option. When directory metadata is later applied through that planted link, the program writes ownership, permission, and timestamp data to files or directories outside the intended destination path. This bypasses normal root confinement protection in the code and allows an attacker who can supply source data to set arbitrary user IDs, group IDs, permissions, or timestamps on chosen files outside the target directory.

Affected Systems

The vulnerable product, rclone, using a version earlier than 1.75.1 and employing the --links flag during a sync is affected. Only these pre‑1.75.1 builds are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires local access: the attacker must control the source contents and run rclone with --links (and optionally --metadata) on a system where the destination is writable. Although no network exposure is required, the flaw can be leveraged for privilege escalation by changing ownership or permissions of critical files outside the intended sync destination.

Generated by OpenCVE AI on September 11, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to rclone version 1.75.1 or later.
  • Avoid using the --links flag when syncing unless absolutely necessary.
  • Ensure that source data does not contain .rclonelink objects before initiating a sync.

Generated by OpenCVE AI on September 11, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f8g7-2xjc-7mfh rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:rclone:rclone:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Rclone
Rclone rclone
Vendors & Products Rclone
Rclone rclone

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.
Title rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
Weaknesses CWE-281
CWE-59
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:44:03.614Z

Reserved: 2026-09-09T19:19:27.407Z

Link: CVE-2026-88016

cve-icon Vulnrichment

Updated: 2026-09-15T14:43:56.614Z

cve-icon NVD

Status : Modified

Published: 2026-09-10T16:18:08.637

Modified: 2026-09-15T15:17:24.307

Link: CVE-2026-88016

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:00:13Z

Weaknesses
  • CWE-281

    Improper Preservation of Permissions

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')