CVE-2026-53795
Last modified
CVE-2026-53795 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Samba | Rsync | < 3.5.0 |
References
- https://github.com/RsyncProject/rsync/releases/tag/v3.5.0Product, Release Notes
- https://www.vulncheck.com/advisories/rsync-arbitrary-file-write-via-temp-dir-link-destRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-53795?
How severe is CVE-2026-53795?
How do I fix CVE-2026-53795?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5379An issue that allowed MCP agents to access certificate infor…3
- CVE-2026-53790rsync before 3.5.0 contains multiple command and argument in…8.1
- CVE-2026-53791rsync daemon before 3.5.0 contains an IP address spoofing vu…9.1
- CVE-2026-53792rsync before 3.5.0 contains an out-of-bounds read vulnerabil…6.5
- CVE-2026-53793rsync before 3.5.0 contains a path confinement bypass vulner…7.4
- CVE-2026-53794rsync before 3.5.0 contains a logic error in --max-alloc han…5.3
- CVE-2026-53796rsync before 3.5.0 contains a time-of-check to time-of-use (…6.3
- CVE-2026-53797rsync before 3.5.0 contains a symlink race condition vulnera…4.7
- CVE-2026-53798rsync before 3.5.0 contains a privilege confusion vulnerabil…5.3
- CVE-2026-53799rsync before 3.5.0 contains a symlink race condition vulnera…6.3
- CVE-2026-5380An issue that could allow an authorized user to view the cle…5.3
- CVE-2026-53800rsync before 3.5.0 contains a symlink race condition vulnera…4.7
Are you affected by CVE-2026-53795?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
