CVE-2026-53795
published 2026-08-13CVE-2026-53795: rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an…
PriorityP345high8.1CVSS 3.1
AVNACLPRNUIRSUCNIHAH
EPSS
0.40%
32.9th percentile
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | <= 3.4.4 | — |
| samba | rsync | < 3.5.0 | 3.5.0 |
| samba | rsync | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv4.07.2HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [epel-all]
bugzilla·2026-08-21·CVSS 8.1
CVE-2026-53795 [HIGH] CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [epel-all]
CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
Bugzilla
CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
bugzilla·2026-08-21·CVSS 8.1
CVE-2026-53795 [HIGH] CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
Discussion:
FEDORA-2026-bfae8723e2 (rsync-3.5.
Bugzilla
CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
bugzilla·2026-08-21·CVSS 8.1
CVE-2026-53795 [HIGH] CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
CVE-2026-53795 rsync-bpc: rsync: Arbitrary file write via --temp-dir or --link-dest options [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
Bugzilla
CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options
bugzilla·2026-08-13·CVSS 8.1
CVE-2026-53795 [HIGH] CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options
CVE-2026-53795 rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by specifying an absolute path via --temp-dir or --link-dest options. The rename-confinement logic is bypassed when these options resolve to paths outside the destination tree, enabling attacker-controlled values to write files to arbitrary locations accessible to the rsync process.
2026-08-13
Published