Path Traversal Vulnerability in Rsync Affected by Symlink Exploitation
CVE-2026-70460

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-70460?

Rsync versions prior to 3.5.0 are susceptible to a path traversal vulnerability caused by the mishandling of symbolic links within the module file tree. This issue arises when using the --partial-dir or --backup-dir options, allowing an attacker with write permissions to manipulate symlinks under the module root. By exploiting this vulnerability, attackers can redirect file writes to unauthorized locations outside the intended module root, posing a significant security risk. Effective remediation requires updating to a patched version or implementing additional restrictions on symlink manipulation.

Affected Version(s)

rsync 2.3.3 <= 3.4.4

rsync 3.5.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

seks99x
.