ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability
ZDI published ZDI-26-626 for a local denial-of-service flaw (CVE-2026-19820, CVSS 6.1) in Backblaze Personal Computer Backup's bzfilelist component.
The Zero Day Initiative published advisory ZDI-26-626 describing a link-following denial-of-service vulnerability in the bzfilelist component of Backblaze Personal Computer Backup. Local attackers must first execute low-privileged code on the target system to trigger the condition. The issue carries a CVSS score of 6.1 and is tracked as CVE-2026-19820.
- Local link-following denial-of-service in Backblaze bzfilelist
- Requires prior low-privileged code execution to exploit
- CVSS 6.1, tracked as CVE-2026-19820
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19820 | Unbootable-System Denial of Service via Link Following in Backblaze Windows Backup Client CVE-2026-19820 is a link-following flaw (CWE-59) in the Backblaze Personal Computer Backup client for Windows, whose backup components (bzserv, bztransmit, bzfilelist, bzbackup, and bzreports) do not properly resolve links in the folders they traverse. A local user can create a link from Backblaze's folder to Windows OS system files during a backup; when the client follows the link, the affected machine can be rendered unbootable. Successful exploitation requires that an administrator-level system change has removed the specific Windows OS security controls that normally govern link resolution, allowing the link to be planted in this way. The impact is loss of availability of the whole system (high impact on the system's ability to boot), not data theft. Exploitation is not currently known: no public PoC exists, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.3%. Do: Update the Backblaze Personal Backup client to the latest vendor release addressing the link-following issues once a fixed version is published (see Backblaze/ZDI advisories ZDI-26-624 through ZDI-26-628). In the meantime, verify that the machine retains the standard Windows security controls around link creation — the flaw requires an administrator-level change that removed them — and restrict which local users can create symlinks or junctions. No in-the-wild exploitation is reported, but monitor Backblaze's advisories for a patched build. | 7.8 | <1% |
| largeroughly hundreds of thousands of Windows installations (Backblaze has historically reported ~500,000+ Computer Backup customers; only Windows systems with the… |
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
This source does not provide full text. Read it at zerodayinitiative.com.