CVE-2026-23778
7.2Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain contains a command injection vulnerability in multiple OS versions, allowing a high-privileged remote attacker to gain root-level access to the system.
Executive summary
A critical command injection vulnerability in Dell PowerProtect Data Domain allows authenticated remote attackers to achieve full root-level system compromise.
Vulnerability
This is a command injection vulnerability (CWE-77) occurring within the Data Domain Operating System. An attacker with high-level administrative privileges can inject arbitrary commands, resulting in full root-level execution on the affected appliance.
Business impact
The vulnerability carries a CVSS score of 7.2, reflecting a significant risk to data integrity and system availability. Because the flaw allows for root-level command execution, an attacker could bypass all security controls, exfiltrate sensitive backup data, destroy stored backups, or install persistent backdoors. This represents a severe threat to business continuity and disaster recovery capabilities.
Remediation
Immediate Action: Update to the patched versions as specified in the Dell Security Advisory DSA-2026-060: version 8.6.0.0 or later, 8.3.1.20 or later, or 7.13.1.50 or later.
Proactive Monitoring: Review system logs for unusual command execution patterns or unexpected administrative activity originating from authenticated sessions.
Compensating Controls: Restrict administrative access to the management interface to trusted management networks and utilize multi-factor authentication to minimize the risk of credential compromise by malicious actors.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The risk of root-level compromise makes this vulnerability a priority for infrastructure teams. Administrators must verify their current DD OS versions against the affected ranges and schedule maintenance to apply the necessary security updates provided by the vendor. Failure to patch these appliances leaves the core of the enterprise backup infrastructure exposed to complete takeover.