CVE-2026-24506
7.2Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain contains an OS command injection vulnerability that allows a high privileged remote attacker to execute arbitrary commands as the root user.
Executive summary
A critical OS command injection vulnerability in Dell PowerProtect Data Domain allows high privileged attackers to achieve full system compromise via arbitrary command execution.
Vulnerability
The software is susceptible to OS command injection (CWE-78) due to improper neutralization of special elements. A high privileged, authenticated remote attacker can exploit this flaw to execute arbitrary commands with root-level privileges.
Business impact
The ability for an attacker to execute commands as the root user represents the highest level of system compromise. Successful exploitation grants the attacker full control over the backup appliance, potentially leading to data destruction, unauthorized access to sensitive backup archives, and complete loss of system integrity. With a CVSS score of 7.2, this vulnerability poses a significant risk to operational continuity and data confidentiality.
Remediation
Immediate Action: Upgrade to the patched versions specified in the Dell security advisory (DSA-2026-060) to remediate the command injection flaw.
Proactive Monitoring: Monitor system logs for unauthorized administrative activity or unexpected execution of OS-level commands by service accounts.
Compensating Controls: Restrict management network access to the Dell PowerProtect Data Domain appliance to known, trusted administrative workstations only to minimize the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the severity of root-level command injection, organizations should prioritize patching their Dell PowerProtect Data Domain instances immediately. Administrators must review the linked vendor advisory for the specific firmware versions relevant to their deployment and apply the updates during the next available maintenance window to neutralize the threat of unauthorized system access.