CVE-2026-24505
7.2Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain versions 8.5 through 8.6 contain an input validation flaw that allows a high privileged remote attacker to execute arbitrary commands with root privileges.
Executive summary
A critical input validation vulnerability in Dell PowerProtect Data Domain allows authenticated high privileged attackers to achieve remote code execution as root.
Vulnerability
The software suffers from improper input validation (CWE-20), which can be leveraged by an attacker with high privileges to execute arbitrary commands. The vulnerability requires a remote attacker to have already established high-level administrative access to the system.
Business impact
The potential for arbitrary command execution with root privileges represents a total compromise of the affected storage appliance. An attacker could exfiltrate sensitive backup data, modify system configurations, or render the backup infrastructure entirely inoperable, leading to significant business disruption. Given the CVSS score of 7.2, this vulnerability is classified as High severity and requires prompt attention to maintain the integrity of enterprise data protection workflows.
Remediation
Immediate Action: Upgrade to version 8.7.0.0 or later, or apply the specific security update for DD OS 8.3.1.30 as outlined in the Dell security advisory DSA-2026-060.
Proactive Monitoring: Review system and audit logs for unauthorized command execution attempts or unusual changes to system configuration files.
Compensating Controls: Ensure that administrative access to the management interface is restricted to authorized personnel only via a secure, segmented management network.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Organizations should prioritize applying the provided vendor patches to move to a non-vulnerable version of the Data Domain OS. Given that this flaw grants root-level access, the risk to backup integrity is significant, and administrators must verify that their update cycle addresses all affected appliances in the environment immediately.