Executive brief
Vinchin Backup & Recovery is a data protection solution used by organizations to back up virtual machines, databases, and physical servers. A security flaw in its communication service allows an unauthenticated attacker to send a specially crafted network packet that can crash the backup system or corrupt its memory. This could lead to a disruption of backup operations and potential loss of service availability.
Technical details
A heap buffer overflow vulnerability exists in the agentlink_server service of Vinchin Backup & Recovery. The issue stems from a failure to validate the 'body_len' field in incoming TCP packets. An unauthenticated remote attacker can provide an arbitrary length value that is passed directly to the recv() function, potentially triggering an overflow of up to 4 GiB. This can result in a denial-of-service (DoS) via process crash or memory corruption. The vulnerability is tracked as CVE-2026-60094 and affects versions up to and including 9.0.0.86562.
Affected products
- Vinchin Backup & Recovery 9.0 through 9.0.0.86562
Timeline
- 2026-07-08: disclosed: Initial disclosure by Code White GmbH
- 2026-07-09: advisory: NVD and VulnCheck published advisory details