ZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
1 affected component
Backblaze Backblaze Personal Computer Backup
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is exposed to exploitation?
Affected installations are exposed to attackers who can already execute low-privileged code on the target system. The issue is local and is described as enabling a denial-of-service condition.
2
What level of access does an attacker need?
The attacker must first obtain the ability to execute low-privileged code on the target system. No remote access vector or additional prerequisites are provided.