PT-2026-71633 · Rsync · Rsync

·

CVE-2026-53795

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description An arbitrary file write issue exists where attackers can write files outside the intended destination tree. This occurs by specifying an absolute path through the --temp-dir or --link-dest options, which bypasses the rename-confinement logic. This allows attacker-controlled values to write files to any location accessible to the rsync process.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95774
CVE-2026-53795
ECHO-3711-8D22-1254
GHSA-M9VJ-637X-V6PQ
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync