Command Injection Vulnerabilities in rsync by Rsync Project
CVE-2026-53790

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-53790?

Rsync versions prior to 3.5.0 are susceptible to multiple command and argument injection vulnerabilities. These vulnerabilities enable attackers to execute arbitrary commands by inputting malicious data through various pathways, such as the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and newline injection within remote-shell commands. Unsanitized user inputs, including hostnames and hostspecs, can be manipulated by injecting shell metacharacters or newline characters, potentially allowing attackers to run commands with the privileges of the rsync process or the invoking user.

Affected Version(s)

rsync 0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

4drez
.