Security Advisory

CVE-2026-19820

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-01 00:13:03
Last updated 2026-09-01 00:13:03
Assigner Bugcrowd
CVSS score 5.8
State PUBLISHED

Description

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.