CVE-2026-19820

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-01 01:16

Updated : 2026-09-11 00:17


NVD link : CVE-2026-19820

Mitre link : CVE-2026-19820

CVE.ORG link : CVE-2026-19820


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')