CVE-2026-70452

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-636CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-23: 109-23
Full discourse1 post
  • Leonid Bugaev@buger

    One of the rsync requirements looked almost embarrassingly simple. A host matching hosts deny must not be admitted. The check failed. When a hostname in a deny rule could not be resolved, rsync skipped the rule. Under that config it failed open. That became CVE-2026-70452, rated HIGH.

    2001073
    5.6K followersView on X

Explore more