PT-2026-71652 · Rsync · Rsync

·

CVE-2026-70452

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions rsync versions 3.1.0 through 3.4.x
Description An access control bypass exists that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule instead of defaulting to a deny decision. This allows attackers to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.
Recommendations Update rsync to version 3.5.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95795
CVE-2026-70452
ECHO-BDC4-0FF5-9A3D
GHSA-6692-28CX-WPQQ
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync