Junglewise Threat Intelligence

CVE-2026-60095: Vinchin Backup & Recovery stack buffer overflow in agentlink_server

CVE-2026-60095 · Severity: medium · CVSS 6.5 · Published 2026-07-09

Executive brief

Vinchin Backup & Recovery is a data protection solution used by organizations to back up virtual machines, databases, and physical servers. A security flaw in its communication service allows an unauthenticated attacker to send a specially crafted network request that can crash the backup service or potentially allow them to take control of the system. This could lead to a disruption of backup operations and impact the availability of critical data recovery services.

Technical details

A stack-based buffer overflow exists in the 'agentlink_server' service of Vinchin Backup & Recovery. The vulnerability is located within the 'ModuleHandShake' function, where the length of the '_listen_uuid' field is measured using 'strlen()' but subsequently copied into a fixed-length stack buffer using 'strcpy()' without proper bounds checking. An unauthenticated remote attacker can exploit this by sending a crafted request with an oversized '_listen_uuid' value. This allows the attacker to overwrite the saved return address on the stack, leading to a process crash (denial of service) or potential control flow hijacking (remote code execution).

Affected products

  • Vinchin Backup & Recovery 9.0 through 9.0.0.86562

Timeline

  • 2026-07-08: disclosed: Initial disclosure by Code White GmbH
  • 2026-07-09: advisory: CVE published and NVD record created

References

Related threats