ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running affected installations of Backblaze Personal Computer Backup are exposed only to attackers who can already execute low-privileged code locally on the target system. This is not described as remotely exploitable.
What level of access does an attacker need?
The attacker must first obtain the ability to execute low-privileged code on the target system. The provided information does not indicate that administrative privileges are required.
What is the impact of successful exploitation?
Successful exploitation allows an attacker to create a denial-of-service condition on the affected installation.