CVE-2026-23776

7.2

Dell · PowerProtect Data Domain

Dell PowerProtect Data Domain is vulnerable to improper certificate validation during login, which may allow a low privileged remote attacker to achieve privilege escalation.

Executive summary

A critical privilege escalation vulnerability in Dell PowerProtect Data Domain allows low privileged remote attackers to gain elevated access due to improper certificate validation.

Vulnerability

The software contains an improper certificate validation flaw (CWE-295) within its certificate based login process. A remote attacker with low privileges can exploit this vulnerability to achieve elevation of privileges on the affected system.

Business impact

Successful exploitation of this vulnerability permits a low privileged user to escalate their permissions, potentially gaining administrative control over the PowerProtect Data Domain system. Given the CVSS score of 7.2, this represents a high severity risk that could lead to unauthorized data access, system configuration changes, or complete compromise of backup infrastructure, resulting in significant operational and security impact.

Remediation

Immediate Action: Update the Data Domain Operating System (DD OS) to version 8.3.1.30, 7.13.1.70, or 8.6.0.0 as specified in the vendor security advisory DSA-2026-060.

Proactive Monitoring: Audit system logs for unusual authentication patterns or unauthorized privilege changes, particularly involving non-administrative user accounts.

Compensating Controls: Restrict network access to the Data Domain management interface to trusted administrative subnets only to limit the exposure of the vulnerable login endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk of privilege escalation within backup management infrastructure presents a significant threat to data integrity and organizational security. IT administrators should prioritize the application of the vendor-supplied patches immediately to remediate the improper certificate validation flaw and prevent potential unauthorized administrative access.

More Dell CVEs

Sources