Arbitrary File Write Vulnerability in Rsync Affects Multiple Versions
CVE-2026-53795

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-53795?

Rsync versions before 3.5.0 are impacted by a vulnerability that permits arbitrary file writing. Attackers can exploit this weakness by using the --temp-dir or --link-dest options with absolute paths, bypassing the rename-confinement logic. This can result in the ability to write files to unintended locations, potentially compromising system integrity and security. Users should review their use of Rsync and consider upgrading to the latest version to mitigate this risk.

Affected Version(s)

rsync 0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

seks99x
fcasal
buger
gregkh
.