rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
References
| Link | Resource |
|---|---|
| https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 | Product Release Notes |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 | Vendor Advisory |
| https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following | Release Notes Third Party Advisory |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-13 15:19
Updated : 2026-08-31 15:26
NVD link : CVE-2026-53802
Mitre link : CVE-2026-53802
CVE.ORG link : CVE-2026-53802
JSON object : View
Products Affected
samba
- rsync
CWE
CWE-61
UNIX Symbolic Link (Symlink) Following
