PT-2026-71627 · Rsync · Rsync

·

CVE-2026-53789

·

Published

2026-08-13

·

Updated

2026-08-26

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description Improper path handling allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree. By sending a crafted file list, an attacker can cause the receiver to reclassify implied parent directory entries or treat synthetic paths as the transfer root. This can be achieved through multiple methods, including implied parent reclassification, synthetic root path construction, non-directory root handling, and legacy protocol behavior below version 30, ultimately resulting in the deletion of files outside the authorized destination directory.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95762
CVE-2026-53789
ECHO-142C-4C54-EFC6
GHSA-FXWG-7HMF-XH5Q
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync