What is CVE-2026-53784?
CVE-2026-53784 is a path traversal vulnerability in rsync versions before 3.5.0. It allows remote clients to access files outside the intended module root when 'use chroot' is disabled and the module root path or its component is a symlink. Affected users should upgrade to rsync version 3.5.0 or later to mitigate the risk.
Azərbaycanca: CVE-2026-53784, rsync-in 3.5.0 versiyasından əvvəlki versiyalarında aşkar edilmiş path traversal zəifliyidir. Bu boşluq "use chroot" deaktiv edildikdə və modul kök yolu simvolik keçid (symlink) olduqda, uzaq müştərilərə nəzərdə tutulmuş qovluq xaricindəki fayllara giriş imkanı verir. Təsirlənən sistemlərdə riski azaltmaq üçün rsync proqramını ən azı 3.5.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
What configuration conditions are required for the CVE-2026-53784 vulnerability to be exploitable in rsync?
To exploit this path traversal vulnerability, the "use chroot" parameter must be disabled and the module root path or its component must be a symbolic link (symlink).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.