ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
1 affected component
Backblaze Personal Computer Backup
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Systems running Backblaze Personal Computer Backup are exposed only if an attacker can already execute low-privileged code locally on the target system. This is not described as a remote, unauthenticated attack.
2
What level of access does an attacker need to exploit it?
The attacker must first obtain the ability to execute low-privileged code on the affected system. Successful exploitation can create a denial-of-service condition.