PT-2026-71654 · Rsync-Ssl+1 · Rsync-Ssl+1

·

CVE-2026-70454

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions rsync versions 3.2.0 through 3.2.3 rsync-ssl versions prior to 3.4.5
Description A TLS certificate validation issue allows on-path attackers to intercept encrypted sessions by presenting self-signed or invalid certificates. This occurs because the software fails to validate server TLS certificates against a trusted Certificate Authority (CA) or verify that the certificate hostname matches. Consequently, an attacker can decrypt or tamper with session content without the client detecting the interference.
Recommendations Update rsync to version 3.5.0 or later. Update rsync-ssl to version 3.4.5 or later.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95777
CVE-2026-70454
ECHO-8D10-95D4-4155
GHSA-3C3X-WW2W-5R5P
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync
Rsync-Ssl