What is CVE-2026-53790?
This CVE covers multiple command injection vulnerabilities in rsync versions before 3.5.0, allowing attackers to execute arbitrary commands via specially crafted input through paths like the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell. Affected users should upgrade to rsync version 3.5.0 or later to mitigate the risk.
Azərbaycanca: Bu CVE rsync proqramının 3.5.0 versiyasından əvvəlki versiyalarında aşkar edilmiş bir neçə command injection zəifliyini əhatə edir ki, bu da təcavüzkarın xüsusi hazırlanmış giriş vasitəsilə sistemdə ixtiyari kod icra etməsinə imkan yaradır. Zəiflik RSYNC_CONNECT_PROG mühit dəyişəni, daemon hooks, rsync-ssl wrapper və remote-shell kimi müxtəlif yollarla istismar olunur. Təsirə məruz qalmamaq üçün rsync-i ən azı 3.5.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What measure should be taken to protect against CVE-2026-53790?
To mitigate the risk of exploitation, it is recommended to upgrade rsync to version 3.5.0 or later.
What are the exploitation paths for CVE-2026-53790?
An attacker can execute arbitrary commands via specially crafted input through various paths such as the RSYNC_CONNECT_PROG environment variable, daemon hooks, the rsync-ssl wrapper, and remote-shell.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.