CVE-2026-26354

8.1

Dell · PowerProtect Data Domain

A stack-based buffer overflow in Dell PowerProtect Data Domain allows unauthenticated remote attackers to achieve arbitrary command execution.

Executive summary

A critical stack-based buffer overflow in Dell PowerProtect Data Domain permits unauthenticated remote attackers to execute arbitrary commands on the affected system.

Vulnerability

This vulnerability is a stack-based buffer overflow (CWE-121) occurring within the Domain Operating System. It allows an unauthenticated attacker to remotely trigger the flaw and gain the ability to execute arbitrary commands.

Business impact

The ability for an unauthenticated remote attacker to execute arbitrary commands represents a total compromise of the affected storage system. Given the CVSS score of 8.1, this vulnerability poses a high risk to data confidentiality, integrity, and availability. Successful exploitation could lead to unauthorized data access, system disruption, or the potential for lateral movement within the network.

Remediation

Immediate Action: Update the affected Dell PowerProtect Data Domain systems to the vendor-specified fixed versions listed in the Dell security advisory DSA-2026-060.

Proactive Monitoring: Monitor system logs for unusual process activity or attempts to access administrative functions from unauthorized remote IP addresses.

Compensating Controls: Restrict network access to the management interface of the PowerProtect Data Domain to trusted management subnets only, utilizing firewall rules to block unsolicited external traffic.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of remote code execution, organizations must prioritize the application of the vendor-provided security updates. Failure to patch these systems leaves critical data infrastructure vulnerable to total compromise by remote attackers. Administrators should verify their current firmware version against the affected release ranges and apply the recommended patches immediately to mitigate this risk.

More Dell CVEs

Sources