What is CVE-2026-53795?
rsync versions before 3.5.0 contain an arbitrary file write vulnerability via the --temp-dir or --link-dest options, allowing attackers to write files outside the intended destination tree. Users should immediately upgrade to rsync 3.5.0 or later.
Azərbaycanca: rsync 3.5.0-dan əvvəl versiyalarda --temp-dir və ya --link-dest opsiyaları vasitəsilə xarici fayl yazma (arbitrary file write) zəifliyi aşkarlanıb. Bu, hücumçulara təyinat qovluğundan kənarda fayl yazmağa imkan verir. istifadəçilər dərhal rsync-i 3.5.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of rsync are affected by CVE-2026-53795?
The vulnerability exists in rsync versions before 3.5.0.
What does this vulnerability allow attackers to do?
It allows attackers to write files outside the intended destination tree via the --temp-dir or --link-dest options.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.