CVE-2026-23774
7.2Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain running specific versions of DD OS contains an OS command injection vulnerability, allowing high privileged remote attackers to execute arbitrary commands.
Executive summary
Dell PowerProtect Data Domain contains a critical OS command injection vulnerability that allows high privileged remote attackers to achieve arbitrary command execution on the system.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) where improper neutralization of special elements allows a remote attacker with high privileges to execute arbitrary commands on the underlying operating system.
Business impact
The ability for an attacker to execute arbitrary commands on a data protection appliance poses a severe risk to organizational data integrity and availability. Given the CVSS score of 7.2, this vulnerability represents a high-severity threat that could lead to full system compromise, unauthorized access to sensitive backup data, or total service disruption.
Remediation
Immediate Action: Upgrade the affected Dell PowerProtect Data Domain systems to the vendor-specified patched versions, such as 8.6.0.0, 8.3.1.20, or 7.13.1.50, as detailed in the official Dell security advisory DSA-2026-060.
Proactive Monitoring: Audit administrative access logs for unusual command execution patterns or unauthorized configuration changes initiated by high-privilege accounts.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only and ensure that management traffic is segmented from the primary production network.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Dell PowerProtect Data Domain should prioritize the application of the vendor-provided firmware updates to address this command injection flaw. Given the potential for total system compromise, administrators must verify the integrity of their backup infrastructure by applying these patches and reviewing audit logs for signs of unauthorized administrative activity.