CVE-2026-19820

Summary

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.

Affected Software

VendorProductVersion RangeStatus
BackblazeBackblaze Client10.0.0.1029affected
BackblazeBackblaze Client10.0.1.10307affected
BackblazeBackblaze Client10.0.2.1047affected

Weaknesses

  • CWE-59 Improper Link Resolution Before File Access

References