ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzbackup component of Backblaze Personal Computer Backup.
The Zero Day Initiative published advisory ZDI-26-624 for a denial-of-service vulnerability in Backblaze Personal Computer Backup's bzbackup component. A local attacker must first gain the ability to run low-privileged code on the target system to trigger the link-following flaw. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-19820.