CVE-2026-70463
published 2026-08-13CVE-2026-70463: rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.36%
29.5th percentile
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| rsyncproject | rsync | 3.1.0 – 3.4.4 | — |
| samba | rsync | — | — |
| samba | rsync | >= 3.1.0 < 3.5.0 | 3.5.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
bugzilla·2026-08-24·CVSS 8.1
CVE-2026-70463 [HIGH] CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group members
Bugzilla
CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
bugzilla·2026-08-24·CVSS 8.1
CVE-2026-70463 [HIGH] CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership
Bugzilla
CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [epel-all]
bugzilla·2026-08-24·CVSS 8.1
CVE-2026-70463 [HIGH] CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [epel-all]
CVE-2026-70463 rsync-bpc: rsync: Authorization bypass via `auth users` directive parsing [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membershi
Bugzilla
CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing
bugzilla·2026-08-13·CVSS 8.1
CVE-2026-70463 [HIGH] CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing
CVE-2026-70463 rsync: rsync: Authorization bypass via `auth users` directive parsing
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.
2026-08-13
Published