What is CVE-2026-53783?
rsync versions before 3.5.0 contain a TOCTOU race condition in the rrsync restricted shell wrapper. This vulnerability allows authenticated clients to escape directory restrictions by substituting a symlink after validation but before transfer, potentially accessing unintended files. Immediate update to version 3.5.0 is recommended.
Azərbaycanca: rsync-in 3.5.0-dən əvvəlki versiyalarında 'rrsync' məhdud shell wrapper-da TOCTOU (yoxlama zamanı ilə istifadə zamanı) yarış şərti zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş müştərilərə, validasiyadan sonra simvolik keçid qoymaqla kataloq məhdudiyyətlərindən yayınmağa imkan verir. Dərhal 3.5.0 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which rsync component is affected by CVE-2026-53783?
This vulnerability is found in the `rrsync` restricted shell wrapper.
How can an attacker bypass directory restrictions using CVE-2026-53783?
An authenticated client can exploit a TOCTOU race condition by substituting a symlink after validation but before the file transfer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.