CVE-2026-60095 Details
Description
Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server service that allows unauthenticated remote attackers to overwrite the saved return address by supplying an oversized _listen_uuid field that is measured via strlen() and copied without bounds checking into a fixed-length stack buffer using strcpy(). Attackers can send a crafted request with a malicious _listen_uuid value to corrupt the stack and achieve process crash or potential control flow hijack without requiring authentication.
A stack buffer overflow vulnerability has been identified in Vinchin Backup & Recovery versions through 9.0.0.86562. The issue resides in the ModuleHandShake function of the agentlink_server service, where unauthenticated remote attackers can exploit an oversized _listen_uuid field. This field is improperly validated and copied into a fixed-length stack buffer using strcpy(), allowing attackers to overwrite the saved return address. Exploitation of this vulnerability can lead to a process crash or potentially hijack control flow.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://code-white.com/public-vulnerability-list/ | [email protected] | BundleTechnical Description |
| https://www.vinchin.com/news/vinchin-backup-recovery-9-0.html | [email protected] | Company NewsVendor |
| https://www.vulncheck.com/advisories/vinchin-backup-recovery-stack-buffer-overflow-via-modulehandshake | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vinchin Backup & Recovery | <= 9.0.0.86562 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion