PT-2026-71625 · Rsync · Rsync

·

CVE-2026-53786

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description Authenticated clients can bypass module-level filter restrictions by providing malicious --filter merge file directives. During filter evaluation, attackers can inject client-side merge file directives to create rules that override the restrictions set by the daemon module, allowing unauthorized access to files that were intended to be excluded.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95822
CVE-2026-53786
ECHO-CC28-5BD9-6CCA
GHSA-MRC3-6CWX-HCH6
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync