CVE-2026-53791Disclosure(samba / rsync)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samba rsync systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized access that would otherwise be blocked based on their real source address.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rsync

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
rsync

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - rsync Daemon IP Spoofing via PROXY Protocol Header (CVE-2026-53791) The rsync daemon before 3.5.0 trusts the source address in a PROXY protocol header without validation. An unauthenticated attacker who can connect directly to rsyncd can send a crafted PROXY header with a forged source IP to bypass hosts allow / hosts deny rules and reach modules that should be blocked by their real IP. This is an access-control bypass rather than direct code execution, so the impact depends on what the exposed rsync modules allow, read-only mirror versus writable. It applies where the daemon accepts PROXY protocol. CVSS 9.1. 👉Upgrade rsync to 3.5.0; don't rely on IP allow/deny alone (use rsync auth), and only accept PROXY headers from trusted upstreams.

    Post summary

    The post announces a critical rsync daemon flaw that allows IP spoofing via PROXY headers, offers technical details, and recommends upgrading to 3.5.0 with additional mitigations.

    0000099
    288 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsambarsync---

Explore more