ZDI-CAN-29326: ZDI-26-626: Backblaze Personal Computer Backup bzfilelist Link Following Denial-of-Service Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
1 affected component
Backblaze Personal Computer Backup
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Systems running Backblaze Personal Computer Backup are exposed if an attacker can already execute low-privileged code locally on the target. It is not described as remotely exploitable.
2
What level of access does an attacker need?
The attacker must first obtain the ability to execute low-privileged code on the affected system. The disclosed impact is denial of service.