rsync < 3.5.0 Arbitrary File Read via Symlink Following
Published Aug 13, 2026
8.4
HIGHCVSS 4.0
EPSS 0.24%
Description
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
Affected products
-
Affected
- ≥ 0, ≤ 3.4.4
Unaffected
- 3.5.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| RsyncProject | Rsync | unaffected | Affected
Unaffected
|
No data.
Red Hat Enterprise Linux 10
rsync-0:3.5.0-3.el10_2
Fixed · RHSA-2026:67463
Red Hat Enterprise Linux 9
rsync-0:3.2.7-1.el9_8
Fixed · RHSA-2026:67462
Red Hat Enterprise Linux 9
rsync-0:3.2.7-1.el9_8
Fixed · RHSA-2026:67462
Red Hat Enterprise Linux 6
rsync
Affected
Red Hat Enterprise Linux 7
rsync
Affected
Red Hat Enterprise Linux 8
rsync
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync-0:3.5.0-3.el10_2 | Fixed | RHSA-2026:67463 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.7-1.el9_8 | Fixed | RHSA-2026:67462 |
| Red Hat Enterprise Linux 9 | rsync-0:3.2.7-1.el9_8 | Fixed | RHSA-2026:67462 |
| Red Hat Enterprise Linux 6 | rsync | Affected | n/a |
| Red Hat Enterprise Linux 7 | rsync | Affected | n/a |
| Red Hat Enterprise Linux 8 | rsync | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A symlink-following vulnerability in rsync allows a local, low-privileged attacker to read arbitrary files accessible to the rsync daemon. The issue occurs when rsync improperly handles input configuration files, such as --files-from or --password-file. Exploitation requires a non-default configuration where the attacker can either control the input file paths or plant symlinks within the daemon's module root.
Red Hat mitigation
Ensure the rsync daemon runs with the principle of least privilege, enabling use chroot = yes to securely jail the process to its module tree. Restrict write access for daemon configuration directories and files specified by --files-from or --password-file to trusted administrators only. When running rsync outside of daemon mode, ensure users only process input files originating from trusted, non-world-writable directories.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-53802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2515416 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-58088 Advisory
- https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 release-notesProductRelease Notes
- https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 exploitvendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-53802
- https://www.cve.org/CVERecord?id=CVE-2026-53802
- https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following third-party-advisoryRelease NotesThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-53802 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2515416 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-58088 | Advisory | |
| https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 | release-notesProductRelease Notes | |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 | exploitvendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-53802 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-53802 | ||
| https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following | third-party-advisoryRelease NotesThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data