← Back to CVE search

CVE-2026-23778

Dell PowerProtect Data Domain

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to gain root-level access.

CVSS 7.2EPSS 1.1400000000000001%Risk 0.79
View source
Published
2026-04-17 09:16:05
Affected versions
>=7.7.1.0,<8.6
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H