← Vulnerability feed

Vulnerability record · CVE-2026-88016 · published 10 September 2026

CVE-2026-88016: Rclone link following vulnerability

Rclone · Rclone

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.

7.1 CVSS 3.1 High EPSS 0.27% · top 82.7% CWE-59 · Link followingCWE-281 · CWE-281
7.1CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
15 Sep 2026Last modified by NVD

Description

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through that path. MkdirMetadata, writeMetadataToFile, and setTimes operate when Directory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and birth-time handling can bypass os.Root confinement and follow the symlink. An attacker controlling source contents can therefore apply selected ownership, permissions, modification times, or birth times to a file or directory outside the destination, with --metadata required for chmod and chown while modification time is applied by the normal directory workflow. This issue is fixed in version 1.75.1.

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-88016 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-88018Rclone improper authentication vulnerabilityrclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 config…EPSS 0.75%9.8CVE-2026-49980Rclone missing authentication for critical function vulnerabilityRclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --…EPSS 0.78%9.2CVE-2026-41176Rclone missing authentication for critical function vulnerabilityRclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is expose…EPSS 3.2%9.2CVE-2026-41179Rclone os command injection vulnerabilityRclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to…EPSS 5.3%8.8CVE-2026-59733Rclone path traversal vulnerabilityRclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --…EPSS 0.55%8.8CVE-2026-54572Rclone link following vulnerabilityRclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclon…EPSS 0.40%7.5CVE-2020-28924Rclone vulnerabilityAn issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak pas…EPSS 1.4%7.5CVE-2018-12907Rclone information exposure vulnerabilityIn Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of an…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-88016), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.