CVE-2026-43617
MEDIUMDescription
Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| samba | rsync |
References
Frequently Asked Questions
What is CVE-2026-43617? +
How severe is CVE-2026-43617? +
What products are affected by CVE-2026-43617? +
How do I check if I'm vulnerable to CVE-2026-43617? +
Related Vulnerabilities
DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in …
The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This …
Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if …
A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, …
(conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 and below, …
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me …