ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzserv component of Backblaze Personal Computer Backup.
The Zero Day Initiative published advisory ZDI-26-625 for a denial-of-service vulnerability in Backblaze Personal Computer Backup's bzserv component. A local attacker must already be able to execute low-privileged code on the system to trigger the flaw, which involves link following. ZDI assigned a CVSS score of 6.1 and the CVE identifier CVE-2026-19820.
- Local attackers with low-privileged code execution can cause a denial-of-service condition.
- The flaw involves link following in the bzserv backup component.
- ZDI assigned CVSS 6.1 under CVE-2026-19820.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19820 | Unbootable-System Denial of Service via Link Following in Backblaze Windows Backup Client CVE-2026-19820 is a link-following flaw (CWE-59) in the Backblaze Personal Computer Backup client for Windows, whose backup components (bzserv, bztransmit, bzfilelist, bzbackup, and bzreports) do not properly resolve links in the folders they traverse. A local user can create a link from Backblaze's folder to Windows OS system files during a backup; when the client follows the link, the affected machine can be rendered unbootable. Successful exploitation requires that an administrator-level system change has removed the specific Windows OS security controls that normally govern link resolution, allowing the link to be planted in this way. The impact is loss of availability of the whole system (high impact on the system's ability to boot), not data theft. Exploitation is not currently known: no public PoC exists, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3%. Do: Update the Backblaze Personal Backup client to the latest vendor release addressing the link-following issues once a fixed version is published (see Backblaze/ZDI advisories ZDI-26-624 through ZDI-26-628). In the meantime, verify that the machine retains the standard Windows security controls around link creation — the flaw requires an administrator-level change that removed them — and restrict which local users can create symlinks or junctions. No in-the-wild exploitation is reported, but monitor Backblaze's advisories for a patched build. | 7.8 | <1% |
| largeroughly hundreds of thousands of Windows installations (Backblaze has historically reported ~500,000+ Computer Backup customers; only Windows systems with the… |
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
This source does not provide full text. Read it at zerodayinitiative.com.