High severity7.1NVD Advisory· Published Aug 13, 2026· Updated Aug 31, 2026
CVE-2026-53784
CVE-2026-53784
Description
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords4 versionspkg:rpm/almalinux/rsync-daemonpkg:rpm/almalinux/rsync-rrsyncpkg:rpm/opensuse/rsync&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/rsync
< 3.2.7-1.el9_8+ 3 more
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.2.7-1.el9_8
- (no CPE)range: < 3.4.1-160000.6.1
- (no CPE)range: < 3.2.7-1.el9_8
Patches
Vulnerability mechanics
References
3- github.com/RsyncProject/rsync/security/advisories/GHSA-ffg2-fr5g-3rxwnvdVendor Advisory
- www.vulncheck.com/advisories/rsync-path-traversal-via-symlink-module-rootnvdRelease NotesThird Party Advisory
- github.com/RsyncProject/rsync/releases/tag/v3.5.0nvdProductRelease Notes
News mentions
0No linked articles in our index yet.