What is CVE-2026-53803?
rsync versions before 3.5.0 contain a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at predictable output paths like `--log-file` or `--write-batch`. Users should upgrade to rsync 3.5.0 to mitigate this issue.
Azərbaycanca: rsync 3.5.0-dən əvvəlki versiyalarda simvolik keçid (symlink following) zəifliyi mövcuddur ki, bu da yerli hücumçulara `--log-file`, `--write-batch` kimi proqnozlaşdırıla bilən çıxış yollarında simvolik keçid yerləşdirərək ixtiyari faylları üzərinə yazmağa imkan verir. Təsirə məruz qalan sistemlərdə rsync-i 3.5.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of rsync are affected by the CVE-2026-53803 symlink following vulnerability?
rsync versions before 3.5.0 are affected by this vulnerability.
What can a local attacker do by exploiting the CVE-2026-53803 vulnerability?
An attacker can overwrite arbitrary files by placing a symlink at predictable output paths like `--log-file` or `--write-batch`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.