CVE-2026-23775

7.6

Dell · PowerProtect Data Domain

Dell PowerProtect Data Domain appliances are susceptible to the insertion of sensitive information into log files, which could lead to unauthorized credential exposure.

Executive summary

A vulnerability in Dell PowerProtect Data Domain appliances allows a low privileged attacker to potentially obtain sensitive credentials via log file exposure, posing a significant risk to data security.

Vulnerability

This flaw involves the insertion of sensitive information into log files (CWE-532). It requires a low privileged attacker with remote access to the system, and it specifically impacts configurations where the retention lock feature is enabled.

Business impact

The exploitation of this vulnerability can lead to the exposure of administrative credentials, potentially allowing an attacker to escalate privileges or compromise the integrity of protected data. With a CVSS score of 7.6, this is classified as a high severity issue because it directly facilitates unauthorized access to sensitive system functions and protected backups.

Remediation

Immediate Action: Update the Data Domain Operating System to version 8.6.0.0 or 8.3.1.20 or later as specified in the Dell security advisory.

Proactive Monitoring: Review system and audit logs for unusual access patterns or attempts to read sensitive configuration files, particularly by low privileged accounts.

Compensating Controls: Restrict remote access to the management interface to trusted administrative networks and implement strict role-based access control to limit the capabilities of low privileged users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for credential theft and the resulting impact on data integrity, organizations utilizing Dell PowerProtect Data Domain with retention lock enabled must prioritize this update. Applying the provided patches is the only definitive way to prevent the inadvertent logging of sensitive information and mitigate the risk of unauthorized system access.

More Dell CVEs

Sources