Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53786

Опубликовано: 13 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining access to files the module filter was intended to exclude.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*
Версия до 3.5.0 (исключая)

EPSS

Процентиль: 24%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-level filter restrictions by supplying malicious --filter merge file directives. Attackers can inject client-side merge file directives during filter evaluation to introduce rules that supersede daemon module-level restrictions, gaining access to files the module filter was intended to exclude.

msrc
14 дней назад

rsync < 3.5.0 Filter Rule Bypass via --filter Merge Directive

CVSS3: 6.5
debian
24 дня назад

rsyncbefore 3.5.0contains a filter rule bypass vulnerability that allo ...

suse-cvrf
17 дней назад

Security update for rsync

suse-cvrf
20 дней назад

Security update for rsync

EPSS

Процентиль: 24%
0.00313
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863