Link following in Rsync - CVE-2026-53783

 

Link following in Rsync - CVE-2026-53783

Published: August 13, 2026


Vulnerability identifier: #VU142296
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-53783
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and modify files outside the restricted directory.

The vulnerability exists due to improper link resolution before file access and unsafe option allowlisting in the rrsync SSH forced-command wrapper when handling rsync arguments and options in a restricted directory. A remote user can replace a validated path component with a symlink or use dangerous allowed options to disclose sensitive information and modify files outside the restricted directory.

The issue affects restricted non-root directory configurations and does not require user interaction.


Affected software

Rsync

How to mitigate CVE-2026-53783

Install security update from vendor's website.

Rsync - update to 3.5.0

External References

Related Security Bulletins