CVE-2026-53802: rsync < 3.5.0 Arbitrary File Read via Symlink Following
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rsyncto a version that resolves this vulnerability.Fixed in 3.5.0 - Upgrade
Upgrade
rsyncto a version that resolves this vulnerability.Fixed in 3.5.0Patch rsync < 3.5.0 Arbitrary File Read via Symlink Following
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53802?
CVE-2026-53802 has a high severity rating of 7.1.
How do I fix CVE-2026-53802?
To fix CVE-2026-53802, upgrade rsync to version 3.5.0 or later.
What is the risk associated with CVE-2026-53802?
The risk associated with CVE-2026-53802 is categorized as medium risk with a score of 52.
What are the potential impacts of CVE-2026-53802 exploitation?
Exploitation of CVE-2026-53802 could allow an attacker to read sensitive files accessible to the rsync daemon process.
Which versions of rsync are affected by CVE-2026-53802?
CVE-2026-53802 affects all versions of rsync prior to 3.5.0.