CVE-2026-24504
7.2Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain contains an improper input validation vulnerability allowing high privileged remote attackers to execute arbitrary commands with root privileges.
Executive summary
A critical input validation vulnerability in Dell PowerProtect Data Domain allows remote attackers with high privileges to achieve full system compromise via arbitrary command execution.
Vulnerability
This vulnerability involves improper input validation (CWE-20) within the application. It requires an attacker to possess high privileges and remote access to the system to trigger arbitrary command execution with root level permissions.
Business impact
The ability to execute arbitrary commands with root privileges presents a severe risk to organizational data integrity and system availability. Given the CVSS score of 7.2, this vulnerability represents a high risk to administrative systems, potentially leading to unauthorized data exfiltration, permanent loss of backups, or complete system takeover by malicious actors who have already gained elevated access.
Remediation
Immediate Action: Update Dell PowerProtect Data Domain to the fixed versions specified in the vendor security advisory, specifically ensuring environments are at or above 8.6.1.10, 8.3.1.30, or 7.13.1.70.
Proactive Monitoring: Monitor system logs for unauthorized configuration changes or anomalous command execution patterns associated with high privilege accounts.
Compensating Controls: Restrict remote management access to the Data Domain system to trusted administrative networks and implement multi-factor authentication for all high privilege accounts to limit the potential for credential compromise.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The potential for root-level command execution makes this vulnerability a significant security concern for enterprise backup environments. Administrators should prioritize the application of the vendor-supplied updates to the specified versions immediately to eliminate the underlying input validation flaw and secure the administrative interface.