rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Samba
Samba rsync |
|
| CPEs | cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Samba
Samba rsync |
Fri, 14 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsync Project
Rsync Project rsync |
|
| Vendors & Products |
Rsync Project
Rsync Project rsync |
Thu, 13 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroot is disabled and the module root path or a component of it is a symlink. The daemon calls chdir() to the module root at session initialization without resolving symlinks via realpath() or equivalent, causing subsequent relative-path operations to reference files relative to the symlink target rather than the intended module root, enabling unauthorized file access. | |
| Title | rsync < 3.5.0 Path Traversal via Symlink Module Root | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-13T14:34:22.543Z
Updated: 2026-08-15T03:17:19.548Z
Reserved: 2026-06-10T20:14:32.826Z
Link: CVE-2026-53784
Updated: 2026-08-15T03:17:13.988Z
Status : Received
Published: 2026-08-13T15:19:42.190
Modified: 2026-08-15T04:18:21.963
Link: CVE-2026-53784
No data.