CVE-2026-93986

CVE-2026-93986 published: rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent directory reference...

View full NVD advisory → ← Back to CVE watch