CVE-2026-70454 HIGH

CVE-2026-70454: rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode

Vendor Rsyncproject
Product rsync
Weakness CWE-295
Published August 13, 2026
Last update August 13, 2026

CVSS base score

7.6/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.

Key dates

02Disclosure timeline

August 13, 2026 CVE published
August 13, 2026 Record updated