Junglewise Threat Intelligence

CVE-2026-60094: Vinchin Backup & Recovery heap buffer overflow in agentlink_server

CVE-2026-60094 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Executive brief

Vinchin Backup & Recovery is a data protection solution used by organizations to back up virtual machines, databases, and physical servers. A security flaw in its communication service allows an unauthenticated attacker to send a specially crafted network packet that can crash the backup system or corrupt its memory. This could lead to a disruption of backup operations and potential loss of service availability.

Technical details

A heap buffer overflow vulnerability exists in the agentlink_server service of Vinchin Backup & Recovery. The issue stems from a failure to validate the 'body_len' field in incoming TCP packets. An unauthenticated remote attacker can provide an arbitrary length value that is passed directly to the recv() function, potentially triggering an overflow of up to 4 GiB. This can result in a denial-of-service (DoS) via process crash or memory corruption. The vulnerability is tracked as CVE-2026-60094 and affects versions up to and including 9.0.0.86562.

Affected products

  • Vinchin Backup & Recovery 9.0 through 9.0.0.86562

Timeline

  • 2026-07-08: disclosed: Initial disclosure by Code White GmbH
  • 2026-07-09: advisory: NVD and VulnCheck published advisory details

References

Related threats