ZDI-CAN-29327: ZDI-26-624: Backblaze Personal Computer Backup bzbackup Link Following Denial-of-Service Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
1 affected component
Backblaze Personal Computer Backup
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Who is realistically exposed to exploitation?
Systems running Backblaze Personal Computer Backup are exposed only after an attacker can execute low-privileged code locally on the target. This is not described as a remotely exploitable issue.
2
What is the likely impact if the vulnerability is exploited?
Successful exploitation allows an attacker to create a denial-of-service condition on the affected installation.