CVE-2026-70463: CWE-863 Incorrect Authorization in RsyncProject rsync
Rsync versions 3.1.0 through 3.4.4 contain an authorization bypass vulnerability due to improper parsing of the auth users directive. The parser incorrectly tokenizes user lists by commas only, failing to handle group names with spaces correctly. This causes deny rules for groups with spaces in their names to be discarded, allowing authenticated users who should be denied access to connect to restricted modules.
AI Analysis
Technical Summary
CVE-2026-70463 is an authorization bypass vulnerability in RsyncProject's rsync software versions 3.1.0 up to and including 3.4.4. The issue arises from the auth users directive parser, which splits user lists only by commas and does not properly handle entries of the form '@Group Name' when the group name contains spaces. The space causes the parser to split the entry incorrectly, discarding the deny rule associated with that group. Consequently, authenticated users who should be denied access based on group membership can bypass restrictions and connect to restricted modules.
Potential Impact
Authenticated users who would normally be denied access due to group membership restrictions can bypass these controls and gain unauthorized access to restricted rsync modules. This could lead to unauthorized data access or modification depending on the module's permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid using group names with spaces in auth users directives or implement additional access controls outside of rsync to mitigate unauthorized access.
CVE-2026-70463: CWE-863 Incorrect Authorization in RsyncProject rsync
Description
Rsync versions 3.1.0 through 3.4.4 contain an authorization bypass vulnerability due to improper parsing of the auth users directive. The parser incorrectly tokenizes user lists by commas only, failing to handle group names with spaces correctly. This causes deny rules for groups with spaces in their names to be discarded, allowing authenticated users who should be denied access to connect to restricted modules.
CVSS v4.0
Score 8.6high
Affected software
RsyncProject
rsync
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-70463 is an authorization bypass vulnerability in RsyncProject's rsync software versions 3.1.0 up to and including 3.4.4. The issue arises from the auth users directive parser, which splits user lists only by commas and does not properly handle entries of the form '@Group Name' when the group name contains spaces. The space causes the parser to split the entry incorrectly, discarding the deny rule associated with that group. Consequently, authenticated users who should be denied access based on group membership can bypass restrictions and connect to restricted modules.
Potential Impact
Authenticated users who would normally be denied access due to group membership restrictions can bypass these controls and gain unauthorized access to restricted rsync modules. This could lead to unauthorized data access or modification depending on the module's permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should avoid using group names with spaces in auth users directives or implement additional access controls outside of rsync to mitigate unauthorized access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-04T14:52:23.815Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7ddecabf8831d5395d0084
Added to database: 08/13/2026, 15:12:10 UTC
Last enriched: 08/21/2026, 13:31:14 UTC
Last updated: 09/29/2026, 01:47:43 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.