Symlink Race Condition Vulnerability in rsync Affects Users
CVE-2026-53801

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-53801?

Rsync versions prior to 3.5.0 exhibit a vulnerability due to a symlink race condition in the sender's directory scanning process. This flaw permits malicious actors to manipulate symlinks within the scanned directory. When the sender application attempts to access directory entries, an attacker can replace a legitimate symlink with one linking to an unintended directory, thereby allowing unauthorized access to files outside the designated module root during both daemon-mode and standard sender-side operations. Proper awareness and prompt upgrades to patched versions are essential to mitigate this security risk.

Affected Version(s)

rsync 0 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.