Backblaze Personal Computer Backup Vulnerable to Denial-of-Service via Symbolic Link Abuse
A denial-of-service vulnerability in Backblaze Personal Computer Backup allows local attackers with low-privileged code execution to overwrite arbitrary files and crash the service.

The Zero Day Initiative (ZDI) has disclosed a denial-of-service (DoS) vulnerability affecting Backblaze Personal Computer Backup, identified as ZDI-26-624 and assigned CVE-2026-19820. This flaw impacts the bzbackup component and can be exploited by local attackers who have already gained low-privileged code execution on the target system.
The vulnerability stems from a link following issue within the Backblaze Service. Attackers can leverage this by creating a symbolic link, which then allows the service to overwrite arbitrary files on the system. This capability can be used to disrupt normal operations and ultimately lead to a denial-of-service condition, rendering the backup service or the entire system unstable or inaccessible.
The CVSS score for this vulnerability is rated at 6.1, indicating a moderate severity. While it requires local access and prior code execution, the potential for system disruption makes it a significant concern for users relying on Backblaze for data backup and recovery. The ability to overwrite arbitrary files could also potentially lead to further system compromise if critical configuration files or executables are targeted.
Backblaze has addressed this vulnerability in Release Version 10.0.1.1069. Users are strongly advised to update their Backblaze Personal Computer Backup client to this latest version to mitigate the risk. Release notes for the fix can be found on the Backblaze website.
The disclosure timeline indicates that the vulnerability was first reported to the vendor on April 7, 2026. Following a coordinated disclosure process, the advisory was publicly released on September 9, 2026, with an update to the advisory also published on the same day. The vulnerability was discovered by security researcher hamdi.
This incident highlights the ongoing need for diligent security practices, even for backup software. While the vulnerability requires local access, it underscores the importance of securing endpoints against initial compromise, as even seemingly benign access can be escalated to cause significant disruption. Users should ensure their systems are patched not only for external threats but also for internal privilege escalation and service abuse vulnerabilities.
Organizations and individuals using Backblaze Personal Computer Backup should prioritize applying the available update. Regular security audits and prompt patching of all software, especially critical infrastructure components like backup solutions, are essential to maintaining a robust security posture against evolving threats.
The Zero Day Initiative has published details on this vulnerability, assigning it the identifier ZDI-26-628 and a CVSS score of 6.1. The advisory also notes that the vulnerability was fixed in release version 10.0.1.1069 and provides a direct link to the release notes for the patch. The vulnerability was initially reported to the vendor on April 7, 2026, with a coordinated public release on September 9, 2026.
The advisory for this vulnerability, ZDI-26-626, has been updated to include the specific CVE ID CVE-2026-19820. Additionally, the advisory now specifies that the vulnerability is fixed in Release Version 10.0.1.1069, with a direct link to the release notes provided. The disclosure timeline indicates the vulnerability was reported on April 7, 2026, and publicly coordinated on September 9, 2026.
The Zero Day Initiative has published advisory ZDI-26-627 detailing a denial-of-service vulnerability in Backblaze Personal Computer Backup, assigned CVE-2026-19820. This advisory confirms the vulnerability allows local attackers with low-privileged code execution to abuse a symbolic link within the Backblaze Service to overwrite arbitrary files, leading to a denial-of-service condition. The vulnerability has been fixed in release version 10.0.1.1069.
The Zero Day Initiative has publicly disclosed this vulnerability, assigning it the identifier ZDI-26-625 and CVE-2026-19820. The advisory confirms that the issue has been fixed in Backblaze Personal Computer Backup version 10.0.1.1069, and provides a direct link to the release notes for Windows. The vulnerability was initially reported to the vendor on April 7, 2026, with a coordinated public release occurring on September 9, 2026.