Vulnerability Description
Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://code-white.com/public-vulnerability-list/
- https://www.vinchin.com/news/vinchin-backup-recovery-9-0.html
- https://www.vulncheck.com/advisories/vinchin-backup-recovery-heap-buffer-overflo
FAQ
What is CVE-2026-60094?
CVE-2026-60094 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malfor...
How severe is CVE-2026-60094?
CVE-2026-60094 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-60094?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.