---
id: CVE-2026-19820
title: Backblaze Client for Windows Improper Link Resolution Vulnerability
summary: >-
  A vulnerability in the Backblaze Client allows a local user to make the system
  not bootable by creating a link from Backblaze's folder to Windows OS system
  files during a backup. Successful exploitation requires an administrator-level
  sy…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L'
cvssSource: cna
cwe:
  - CWE-59
vendor: Backblaze
product: Backblaze Client
affected:
  - client 10.0.0.1029
  - client 10.0.1.1037
  - client 10.0.2.1047
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-01T15:13:42.323998Z'
published: '2026-09-01'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T23:32:25.536Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-19820'
references:
  - url: >-
      https://www.backblaze.com/computer-backup/docs/backup-client-release-notes-windows
  - url: 'https://www.backblaze.com/status/update'
tags:
  - cve.org
epss: 0.00327
epssPercentile: 0.23164
ingestedAt: '2026-09-11T16:45:47.928Z'
---

## Overview

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls. This vulnerability is due to improper link resolution.

## Affected

- `client 10.0.0.1029`
- `client 10.0.1.1037`
- `client 10.0.2.1047`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
