CVE-2026-53786

Description

A flaw was found in rsync. This vulnerability allows authenticated clients to bypass module-level filter restrictions. By supplying malicious merge file directives, an attacker can inject rules that override the daemon's intended file exclusion policies. This leads to information disclosure, as attackers can gain unauthorized access to files that should have been restricted.

Statement

This Moderate impact flaw in rsync allows an authenticated client to bypass module-level filter restrictions. An attacker with authenticated access to an rsync daemon configured with module filters could supply malicious merge file directives to access files intended to be excluded. This risk is present when rsync is used in daemon mode with active module-level filtering.

Mitigation

To mitigate this issue, restrict network access to the rsync daemon to only trusted clients and networks. If module-level filtering is not essential for your deployment, consider reconfiguring rsync to operate without module filters or avoid running rsync in daemon mode.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.5N/A6.5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityLowN/ALow
Integrity ImpactLowN/ALow
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Understanding the Weakness (CWE)

Integrity

Technical Impact: Unexpected State

Frequently Asked Questions

Want to get errata notifications? Sign up here.