Description
Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.
Published: 2026-07-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow exists in the agentlink_server component of Vinchin Backup & Recovery. The vulnerability is triggered by an unchecked body_len field in a TCP packet, allowing an unauthenticated remote attacker to send a malicious payload that is passed directly to recv(), causing an overflow of up to roughly 4 GiB. This can corrupt heap memory, leading to a process crash or, if crafted with precision, to more severe memory corruption that could alter application behavior. The weakness is classified as CWE‑787.

Affected Systems

The affected product line is Vinchin Backup & Recovery 9.0, with all builds up to and including version 9.0.0.86562 vulnerable. The agentlink_server service is the specific entry point; any host running this service in a 9.0 build is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score of < 1 % suggests a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because it is remotely exploitable without authentication and requires only network connectivity to the agentlink_server port, exposed deployments could suffer denial‑of‑service or exploit memory corruption if an attacker gains sufficient control.

Generated by OpenCVE AI on July 29, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or update that resolves the heap buffer overflow in Vinchin Backup & Recovery 9.0.
  • Restrict network access to the agentlink_server port so that only trusted internal hosts can reach the service, using firewall rules or similar controls.
  • If the agentlink_server service is not essential for backup functions, disable or uninstall it to eliminate the attack vector.

Generated by OpenCVE AI on July 29, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Vinchin
Vinchin backup & Recovery
Vendors & Products Vinchin
Vinchin backup & Recovery

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause process crash or memory corruption by sending a malformed TCP packet with an unchecked body_len field to the agentlink_server service. Attackers can craft a malicious packet that passes an attacker-controlled length directly to recv(), triggering a heap overflow of up to approximately 4 GiB and resulting in process crash or potential memory corruption.
Title Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Vinchin Backup & Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-09T14:43:18.397Z

Reserved: 2026-07-08T13:27:53.029Z

Link: CVE-2026-60094

cve-icon Vulnrichment

Updated: 2026-07-09T14:43:14.342Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:30:03Z

Weaknesses