CVE-2026-26943

7.2

Dell · PowerProtect Data Domain

Dell PowerProtect Data Domain contains an OS command injection vulnerability allowing high privileged remote attackers to execute arbitrary commands with root privileges.

Executive summary

A critical OS command injection vulnerability in Dell PowerProtect Data Domain could allow a high privileged attacker to achieve full system compromise with root-level access.

Vulnerability

This is an OS command injection flaw (CWE-78) occurring in the system management interface. A remote attacker with high-level administrative privileges can inject arbitrary commands that execute with root-level permissions on the underlying operating system.

Business impact

The potential for root-level command execution represents a total compromise of the affected backup infrastructure. Successful exploitation could lead to full data loss, unauthorized access to sensitive backup archives, and complete loss of control over the storage environment. While the CVSS score of 7.2 reflects the requirement for high privileges, the administrative nature of this device makes it a high-value target for lateral movement.

Remediation

Immediate Action: Upgrade to the latest patched version as specified in the Dell security advisory (DSA-2026-060) to remediate the command injection flaw.

Proactive Monitoring: Review system audit logs for unusual command execution patterns or unauthorized changes to system configurations originating from administrative accounts.

Compensating Controls: Restrict access to the management interface to authorized jump boxes or internal management networks to limit the exposure of the administrative portal.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for root-level execution, administrators must prioritize patching this vulnerability during the next scheduled maintenance window. Because this flaw resides in a critical data protection component, failing to apply the update leaves the organization's primary disaster recovery infrastructure susceptible to total takeover.

More Dell CVEs

Sources