Echo: rsync: security update to 3.5.0

high Tenable Self-Hosted Container Security Plugin ID 463814

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users
parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries
of the form @Group Name where the group name contains a space. The space within the group name causes the
parser to split the entry at the space boundary, discarding the deny rule associated with the group. An
authenticated user whose username or group membership would be denied by an @Group Name auth users entry
can connect to a restricted module because the deny rule is silently discarded during parsing.
(CVE-2026-70463)

Solution

Update the rsync library and its related packages to version 3.5.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-70463

Plugin Details

Severity: High

ID: 463814

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.43

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-70463

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.6

Threat Score: 7.3

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/13/2026

Vulnerability Publication Date: 8/13/2026

Reference Information

CVE: CVE-2026-70463

IAVA: 2026-A-0906