Improper Certificate Validation in Rsync - CVE-2026-70454
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and tamper with transmitted data.
The vulnerability exists due to improper certificate validation in the rsync-ssl helper script when establishing TLS connections to an rsync daemon through affected backends. A remote attacker can perform a machine-in-the-middle attack using a certificate that is not properly verified to disclose sensitive information and tamper with transmitted data.
User interaction is required because a user must invoke rsync-ssl.