A vulnerability was found in Home Assistant up to 2026.5.x. It has been declared as critical. This vulnerability affects the function
pathlib.Path.__truediv__ of the component Backup Handler. The manipulation of the argument Name results in path traversal.
This vulnerability was named CVE-2026-64825. The attack may be performed from remote. There is no available exploit.