What is CVE-2026-53786?
rsync before version 3.5.0 contains a filter rule bypass vulnerability allowing authenticated clients to override module-level filter restrictions via malicious '--filter merge file' directives. Affected systems should be upgraded to rsync version 3.5.0 or later to mitigate the risk.
Azərbaycanca: rsync proqramının 3.5.0 versiyasından əvvəlki versiyalarında filter qaydasını yan keçmə zəifliyi aşkar edilib. Autentifikasiya olunmuş istifadəçi '--filter merge file' direktivləri ilə modul səviyyəli məhdudiyyətləri dəf edə bilir. Təsirə məruz qalan sistemlərdə rsync-i ən azı 3.5.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which software is affected by CVE-2026-53786 and what prerequisite is required?
This vulnerability affects rsync versions prior to 3.5.0. Exploiting the vulnerability requires the user to be authenticated on the system.
What measure should be taken to mitigate CVE-2026-53786?
Affected systems should be upgraded to rsync version 3.5.0 or later to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.