rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process. | |
| Title | rsync < 3.5.0 Arbitrary File Read via Symlink Following | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T15:26:40.170Z
Reserved: 2026-06-10T20:14:32.829Z
Link: CVE-2026-53802
Updated: 2026-08-13T15:26:36.288Z
Status : Received
Published: 2026-08-13T15:19:52.850
Modified: 2026-08-13T16:18:07.203
Link: CVE-2026-53802
No data.
OpenCVE Enrichment
Updated: 2026-08-13T17:00:04Z