ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability
ZDI disclosed CVE-2026-19820, a CVSS 6.1 local link-following denial-of-service flaw in the bzserv component of Backblaze Personal Computer Backup.
The Zero Day Initiative published advisory ZDI-26-625 for a denial-of-service vulnerability in Backblaze Personal Computer Backup's bzserv component. A local attacker must already be able to execute low-privileged code on the system to trigger the flaw, which involves link following. ZDI assigned a CVSS score of 6.1 and the CVE identifier CVE-2026-19820.