NVD HIGH: CVE-2026-53803 — rsync before 3.5.0 contains a symlink following vulnerability that allows local ...
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local
CVE-2026-53803