CVE-2026-23853

8.4

Dell · PowerProtect Data Domain

Dell PowerProtect Data Domain systems are susceptible to a weak credentials vulnerability that allows unauthenticated local attackers to gain unauthorized system access.

Executive summary

A critical vulnerability in Dell PowerProtect Data Domain allows unauthenticated local attackers to bypass security controls and gain unauthorized access to the system.

Vulnerability

This vulnerability involves the use of weak credentials within the Data Domain Operating System. An unauthenticated attacker with local access can exploit this flaw to achieve complete unauthorized access to the system.

Business impact

The exploitation of this vulnerability poses a severe risk to data integrity, confidentiality, and availability. Given the CVSS score of 8.4, this flaw is categorized as High severity, as it allows an attacker to gain full control over a critical storage and backup infrastructure component. Unauthorized access could lead to the compromise of sensitive backup data or the total destruction of storage configurations, causing significant operational disruption.

Remediation

Immediate Action: Update the Data Domain Operating System to the versions specified in the Dell Security Advisory DSA-2026-060, specifically ensuring the system is moved to 8.6.0.0, 8.3.1.20, 7.13.1.50, or 2.7.9 as applicable.

Proactive Monitoring: Review system access logs for unauthorized login attempts or unusual administrative activity originating from local interfaces.

Compensating Controls: Restrict physical access to the Data Domain hardware and ensure that only authorized personnel have local console access to the device.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Organizations utilizing Dell PowerProtect Data Domain must prioritize the application of the vendor-supplied security patches detailed in DSA-2026-060. Given the sensitivity of backup infrastructure, failing to address this credential weakness could provide an attacker with a foothold to manipulate or exfiltrate enterprise-wide data. Administrators should verify their current firmware levels immediately and schedule maintenance windows to apply the necessary updates.

More Dell CVEs

Sources