Vulnerability record · CVE-2026-53802 · published 13 August 2026
CVE-2026-53802: Samba rsync vulnerability
Samba · Rsync
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
Description
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the rsync daemon process by exploiting symlink following in input configuration file handling including --files-from, --password-file, and filter merge files. Attackers can place a symlink at a predictable --files-from or --password-file path, or supply a --files-from path that escapes the daemon module root, to read arbitrary files accessible to the rsync process.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/RsyncProject/rsync/releases/tag/v3.5.0 | ProductRelease Notes |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 | Vendor Advisory |
| https://www.vulncheck.com/advisories/rsync-arbitrary-file-read-via-symlink-following | Release NotesThird Party Advisory |
| https://github.com/RsyncProject/rsync/security/advisories/GHSA-4mfr-8jrv-49x4 | Vendor Advisory |
Track CVE-2026-53802 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-53802), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.