High [CVE-2026-70463] Authorization bypass via `auth users` directive parsing
This high-severity Red Hat Linux advisory covers CVE-2026-70463 affecting Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space.
The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.
An authorization bypass flaw was found in the rsync daemon. The auth users directive parser incorrectly handles group names containing spaces due to comma-only tokenization.
This flaw causes deny rules to be silently discarded, allowing an authenticated user to bypass restrictions and gain unauthorized access to restricted modules. The flaw allows an authenticated, but unauthorized, user to access restricted rsync modules due to incorrect parsing of deny rules.
This bypass occurs because the rsync parser fails to properly tokenize group names with embedded spaces, silently discarding intended access restrictions. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Weakness: CWE-863.
- < 3.1.0
- < 3.5.0
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 3.5.0
- rsync-0:3.5.0-3.el10_2
- rsync-0:3.2.7-1.el9_8
- RHSA-2026:67463
- RHSA-2026:67462
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- To prevent this authorization bypass, ensure that no group names containing spaces are used within the `auth users` directive in the `rsyncd.conf` configuration file. Review and update any existing configurations to remove spaces from group names in this directive. After making changes, restart the `rsync` service for the new configuration to take effect. For example, use `systemctl restart rsyncd` if managing the service with systemd. Note that restarting the service will temporarily interrupt active rsync operations.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.