CVE-2026-19820
Received Received - Intake

Backblaze Client Local Privilege Escalation via Improper Link Resolution

Vulnerability report for CVE-2026-19820, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Bugcrowd Inc.

Description

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
backblaze backup_client 10.0.1.1069

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Backblaze Client allows a local user to make the system unbootable by creating a link from Backblaze's folder to critical Windows OS system files during a backup. It occurs due to improper link resolution and requires an administrator-level change that disables specific Windows OS security controls.

Detection Guidance

Detecting this vulnerability requires checking if the Backblaze client version is outdated. On Windows, open Backblaze and go to the 'About...' option in the menu to verify the installed version. Compare it against the latest version mentioned in the release notes (10.0.1.1069). If the version is older, the system may be vulnerable.

Impact Analysis

Exploitation could prevent your system from booting, leading to data loss or system unavailability. An attacker with local access could manipulate system files through this vulnerability.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access or data manipulation through filesystem redirection. If exploited, it may lead to unauthorized changes in system files, which could compromise data integrity and confidentiality. Compliance with these regulations often requires ensuring data protection and preventing unauthorized system modifications.

Mitigation Strategies

Update the Backblaze client to the latest version (10.0.1.1069 or later) immediately. Download the update from Backblaze's official website or use the automatic update feature. For enterprise deployments, use the Windows MSI installer for mass updates. Ensure automatic updates are enabled to prevent future vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19820. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart