CVE-2026-70460: rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.
Security readout for executives and security teams
Plain-English summary
A malicious rsync sender may redirect file writes outside an intended module directory when vulnerable servers use --partial-dir or --backup-dir and a usable symlink exists. This could overwrite sensitive files and compromise confidentiality, integrity, or availability. Exploitation requires a specific configuration and attacker-controlled or pre-existing symlink, but the potential impact is critical.
Executive priority
Prioritize immediate assessment of internet-facing or partner-accessible rsync services. Expedite upgrades where vulnerable versions, relevant directory options, writable modules, and symlinks overlap. Critical impact justifies urgent action, although the required conditions and lack of cited active exploitation make configuration validation essential for accurate prioritization.
Technical view
rsync versions 2.3.3 through 3.4.x can improperly follow symlinks inside a module tree when processing --partial-dir or --backup-dir. A sender able to place or leverage such a symlink may traverse beyond the module root and achieve arbitrary file writes relative to its parent. CWE-22 and CWE-59 apply. Version 3.5.0 is identified as the corrected release.
Likely exposure
Highest exposure exists on network-accessible rsync services running 2.3.3 through 3.4.x, using --partial-dir or --backup-dir, and accepting writes into module trees containing attacker-controlled or trusted symlinks. Systems without those options or symlink conditions may not be exploitable through this issue. Confirm actual daemon, module, and transfer configurations.
Exploitation context
The supplied record has CVSS 4.0 score 9.2, but attack complexity is high because exploitation depends on configuration and a suitable symlink. The bundle states KEV is false and provides no evidence of active exploitation. Treat exposed qualifying deployments urgently without claiming exploitation has occurred.
Researcher notes
The source bundle describes a path traversal and symlink-following flaw affecting rsync 2.3.3 before 3.5.0. The listed affected-version metadata is ambiguous because it separately shows 2.3.3 and 3.5.0 with a default unaffected status; therefore, use the narrative range and vendor advisory, then confirm downstream package backports. No public exploitation evidence is supplied.
Mitigation direction
Upgrade affected rsync installations to version 3.5.0 or later after compatibility testing.
Until upgraded, avoid --partial-dir and --backup-dir on writable or untrusted module trees.
Restrict sender access and remove unnecessary write permissions from exposed rsync modules.
Review vendor guidance and downstream distribution advisories for supported package updates.
Validation and detection
Inventory rsync versions and identify installations earlier than 3.5.0 but not earlier than 2.3.3.
Inspect daemon, module, service, and job configurations for --partial-dir or --backup-dir.
Audit affected module trees for symlinks, especially paths writable by senders.
Check filesystem logs and integrity monitoring for unexpected writes outside module roots.
Verify the deployed binary reports version 3.5.0 or later after remediation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
2CVSS vectors
3Timeline events
1ADP providers
4Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
2 official scores
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.