ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzreports component of Backblaze Personal Computer Backup.
The Zero Day Initiative published advisory ZDI-26-628 for a denial-of-service vulnerability in Backblaze Personal Computer Backup's bzreports component. A local attacker must first obtain the ability to execute low-privileged code on the system to exploit the link-following flaw. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-19820.