CVE-2020-8289

HIGH

Backblaze <7.0.1.433-7.0.1.434 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-8289. PoCs published by geffner, X1cT34m.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and file validation flaws to execute arbitrary code.

Description

Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code execution via client update functionality.

Exploits (2)

nomisec WORKING POC 11 stars
by geffner · poc
https://github.com/geffner/CVE-2020-8289

This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and file validation flaws to execute arbitrary code.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Backblaze for Windows and macOS (versions prior to 7.0.1.433 and 7.1.0.434)
No auth needed
Prerequisites: DNS spoofing or hosts file modification to redirect Backblaze update traffic to attacker-controlled server · Self-signed SSL certificate for the attacker's server
devstral-2 · analyzed Feb 18, 2026 Full analysis →
github WORKING POC 4 stars
by X1cT34m · cpoc
https://github.com/X1cT34m/CVE-and-PoC/tree/main/2020/CVE-2020-8289

This repository contains a functional proof-of-concept exploit for CVE-2020-8289, demonstrating remote code execution (RCE) as SYSTEM/root via Backblaze's update mechanism. The exploit leverages SSL certificate validation bypass and a weak file validation check to execute arbitrary code.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Backblaze for Windows and macOS (versions prior to 7.0.1.433 and 7.1.0.434)
No auth needed
Prerequisites: DNS spoofing or hosts file modification to redirect Backblaze update traffic to attacker-controlled server · Self-signed SSL certificate for the attacker's server
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (6)

Core 6
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/818853
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/W0THXbcX5V8
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/57
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Dec/58

Scores

CVSS v3 7.8
EPSS 0.2054
EPSS Percentile 95.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-295
Status published
Products (2)
backblaze/backblaze < 7.0.1.433
backblaze/backblaze < 7.0.1.434
Published Dec 27, 2020
Tracked Since Feb 18, 2026