CVE-2026-19820

EUVD-2026-68916
A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
BugcrowdCNA
5.8 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.28%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
backblazebackblaze
10.0.0.1029
CNA
backblazebackblaze
10.0.1.10307
CNA
backblazebackblaze
10.0.2.1047
CNA