Bug 2531548 (CVE-2026-88046)
| Summary: | CVE-2026-88046 github.com/rclone/rclone: rclone: Unauthorized data modification via path traversal in source object names | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | aazores, cmah, eaguilar, ebaron, gparvin, jmatsuok, jtolenti, pjindal, rhaigner |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rclone, a command-line program for syncing files. This vulnerability allows an attacker to bypass configured directory restrictions by including parent-directory segments (e.g., '..') in source object names. When a specially crafted source object is uploaded or copied, it can enable unauthorized access or modification of data outside the intended storage location. This could lead to data being written to unintended buckets, shares, or filesystem paths accessible by the victim's credentials.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2531799, 2531800 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-10 16:32:26 UTC
|