CVE-2026-53803
published 2026-08-13CVE-2026-53803: rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.7th percentile
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | <= 3.4.4 | — |
| samba | rsync | < 3.5.0 | 3.5.0 |
| samba | rsync | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.5HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
bugzilla·2026-08-19·CVSS 7.8
CVE-2026-53803 [HIGH] CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privilege
Bugzilla
CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [epel-all]
bugzilla·2026-08-19·CVSS 7.8
CVE-2026-53803 [HIGH] CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [epel-all]
CVE-2026-53803 rsync-bpc: rsync: Local Privilege Escalation via Symlink Following [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges
Bugzilla
CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
bugzilla·2026-08-19·CVSS 7.8
CVE-2026-53803 [HIGH] CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges su
Bugzilla
CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following
bugzilla·2026-08-13·CVSS 7.8
CVE-2026-53803 [HIGH] CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following
CVE-2026-53803 rsync: rsync: Local Privilege Escalation via Symlink Following
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
2026-08-13
Published