ZDI-CAN-29324: ZDI-26-625: Backblaze Personal Computer Backup bzserv Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to execute low-privileged code locally on the target system. The provided information does not indicate that remote, unauthenticated attackers can exploit it.
What is the impact of successful exploitation?
Successful exploitation can create a denial-of-service condition on an affected installation of Backblaze Personal Computer Backup.
How is this vulnerability tracked?
This issue is assigned CVE-2026-19820 and is identified by ZDI as ZDI-26-625. The provided data assigns it a CVSS rating of 6.1.