Filter Rule Bypass in Rsync Affects Multiple Versions from Rsync Project
CVE-2026-53786
6.9MEDIUM
What is CVE-2026-53786?
Rsync prior to version 3.5.0 is susceptible to a filter rule bypass vulnerability, which allows authenticated clients to manipulate module-level filter settings. This exploitation occurs when attackers introduce malicious --filter merge file directives, effectively overriding existing restrictions established by the daemon. Consequently, they may gain unauthorized access to files that the filter was explicitly designed to protect against.
Affected Version(s)
rsync 0 <= 3.4.4
rsync 3.5.0
