CVE-2026-43617
Last modified
CVE-2026-43617 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Rsync | <= 3.4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-43617?
How severe is CVE-2026-43617?
How do I fix CVE-2026-43617?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-43584OpenClaw before 2026.4.10 contains an insufficient environme…8.8
- CVE-2026-43585OpenClaw before 2026.4.15 captures resolved bearer-auth conf…9.8
- CVE-2026-4359A compromised third party cloud server or man-in-the-middle …3.7
- CVE-2026-4360In the Tarfile.extract() function, the filter parameter is n…5.3
- CVE-2026-43606Observable Timing Discrepancy in the AMD Vitis Libraries ECD…8.5
- CVE-2026-43616Detect-It-Easy prior to 3.21 contains a path traversal vulne…7.8
- CVE-2026-43618Rsync version 3.4.2 and prior contain an integer overflow vu…8.1
- CVE-2026-43619Rsync version 3.4.2 and prior contain symlink race condition…7.2
- CVE-2026-4362The ElementsKit Elementor Addons plugin for WordPress is vul…6.5
- CVE-2026-43620Rsync version 3.4.2 and prior contain a receiver-side out-of…5.5
- CVE-2026-43622llama.cpp builds b1886 through b7445 contain a double free v…8.5
- CVE-2026-43623microtar through 0.1.0 contains a stack-based buffer overflo…8.8
Are you affected by CVE-2026-43617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
