Back

HIGH

rsync < 3.5.0 Arbitrary File Read via Symlink Following

Published Aug 13, 2026

Description

rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.

Affected products

Remediation

Red Hat statement

A symlink-following vulnerability in rsync allows a local, low-privileged attacker to read arbitrary files accessible to the rsync daemon. The issue occurs when rsync improperly handles input configuration files, such as --files-from or --password-file. Exploitation requires a non-default configuration where the attacker can either control the input file paths or plant symlinks within the daemon's module root.

Red Hat mitigation

Ensure the rsync daemon runs with the principle of least privilege, enabling use chroot = yes to securely jail the process to its module tree. Restrict write access for daemon configuration directories and files specified by --files-from or --password-file to trusted administrators only. When running rsync outside of daemon mode, ensure users only process input files originating from trusted, non-world-writable directories.

Weaknesses (2)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 13, 2026
Updated Aug 14, 2026
Reserved Jun 10, 2026

CISA Vulnrichment

Updated Aug 13, 2026

NVD

Status Analyzed
Modified Aug 31, 2026

Red Hat

Severity Important
Public date Aug 13, 2026
Bugzilla 2515416

ENISA EUVD

Assigner VulnCheck
Published Aug 13, 2026
Updated Aug 14, 2026

GitHub

No data