A vulnerability was found in RsyncProject rsync up to 3.4.x and classified as problematic . Affected by this issue is the function acl_set_file of the component Symlink . The manipulation results in race condition. This vulnerability is known as CVE-2026-53799 . Attacking locally is a requirement. No exploit is available. It is suggested to upgrade the affected component.