A vulnerability was found in RsyncProject rsync up to 3.4.4 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality of the component Input Configuration File Handler . The manipulation of the argument files-from/password-file/filter merge files results in symlink following. This vulnerability was named CVE-2026-53802 . The attack may be performed from remote. There is no available exploit. It is recommended to upgrade the affected component.