Junglewise Threat Intelligence

CVE-2026-19820: Backblaze Client improper link resolution denial of service

CVE-2026-19820 · Severity: info · Published 2026-09-01

Executive brief

Backblaze Client is a backup application that automatically protects user files. A local user with administrative access can exploit improper handling of symbolic links in the backup process to make the Windows system unbootable by redirecting the backup to overwrite critical operating system files. This causes complete loss of system availability and requires recovery intervention.

Technical details

The vulnerability is an improper link resolution flaw in Backblaze Client's backup engine. A local administrator can create a symbolic link from Backblaze's backup folder to Windows system directories; when the backup process follows the link without proper validation, it overwrites critical OS files required for boot. The attack vector is local, requires administrator privileges, and also requires that the target system has administrative-level security controls disabled (such as reparse point restrictions). Successful exploitation renders the system unbootable. Patch availability is not specified in available sources.

Affected products

  • Backblaze Client <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References