ZDI-CAN-29328: ZDI-26-628: Backblaze Personal Computer Backup bzreports Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker must already be able to execute low-privileged code on the target system. The issue is therefore relevant to systems where untrusted local code execution is possible.
What is the expected impact of successful exploitation?
Successful exploitation allows a local attacker to create a denial-of-service condition on an affected installation of Backblaze Personal Computer Backup. The provided information does not indicate data disclosure, data modification, or privilege escalation.