CVE-2026-53789
rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope of --delete operations beyond the intended destination subtree by sending a crafted file list that causes rsync to reclassify implied parent directory entries or treat synthetic paths as the transfer root. Attackers can exploit multiple variants including implied parent reclassification, synthetic root path construction, legacy protocol behavior below version 30, and non-directory root handling to cause the receiver to delete files outside the authorized destination directory.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-807
- Published
- 2026-08-13
- Last modified
- 2026-08-15
Affected products
- RsyncProject rsync
- RsyncProject rsync
Weakness type
Related vulnerabilities
- CVE-2026-87479 — Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a...
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2026-63041 — Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
- CVE-2026-54730 — authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-64934 — Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
- CVE-2026-19579 — Snipe-IT Checkout Request Cancellation IDOR