PT-2026-71660 · Rsync · Rsync

·

CVE-2026-70460

·

Published

2026-08-13

·

Updated

2026-09-02

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions rsync versions 2.3.3 through 3.4.x
Description A path traversal issue exists where a malicious sender can escape the module root by exploiting symlinks within the module file tree. This occurs when using the --partial-dir or --backup-dir options. Attackers who can place a symlink under the module root, or leverage an existing trusted symlink, can direct file writes to locations outside the intended module root, resulting in arbitrary file write relative to the module root parent.
Recommendations Update rsync to version 3.5.0 or later. Avoid using the --partial-dir and --backup-dir options until the software is updated.

Exploit

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95828
CVE-2026-70460
ECHO-D837-AA5E-CF4E
GHSA-W3XF-J2R2-GV4X
OPENSUSE-SU-2026:21650-1
SUSE-SU-2026:23253-1
SUSE-SU-2026:23254-1
SUSE-SU-2026:23289-1
SUSE-SU-2026:23323-1
SUSE-SU-2026:3634-1
SUSE-SU-2026:3657-1

Affected Products

Rsync