PT-2026-71623 · Rsync · Rsync

CVE-2026-53784

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description A path traversal issue exists when the use chroot setting is disabled and the module root path, or any of its components, is a symbolic link (a file that points to another file or directory). During session initialization, the daemon uses the chdir() function to enter the module root without resolving symbolic links through realpath() or a similar method. This causes relative-path operations to reference files based on the symbolic link target instead of the intended module root, allowing remote clients to access files outside the designated directory.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95852
CVE-2026-53784
ECHO-660C-EF4B-715C
GHSA-FFG2-FR5G-3RXW
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync