PT-2026-71640 · Rsync · Rsync

·

CVE-2026-53802

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions prior to 3.5.0
Description An arbitrary file read issue exists due to improper symlink following during the handling of input configuration files. Attackers can read files accessible to the rsync daemon process by placing a symlink at a predictable path for --files-from or --password-file, or by providing a --files-from path that escapes the daemon module root. This affects the processing of --files-from, --password-file, and filter merge files.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95810
CVE-2026-53802
ECHO-2077-1568-C26E
GHSA-4MFR-8JRV-49X4
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync