CVE-2026-26944
8.8Dell · PowerProtect Data Domain
Dell PowerProtect Data Domain contains a missing authentication vulnerability that allows remote attackers to execute arbitrary commands with root privileges when a specific user action is performed.
Executive summary
A critical missing authentication vulnerability in Dell PowerProtect Data Domain could allow remote attackers to achieve full system compromise via arbitrary command execution.
Vulnerability
This is a missing authentication for critical function (CWE-306) vulnerability. While the flaw is accessible to remote actors, successful exploitation requires an authenticated user to perform a specific action, effectively acting as a bridge for the attacker to achieve root-level command execution.
Business impact
The potential for arbitrary command execution with root privileges represents a total compromise of the affected storage system. Given the CVSS score of 8.8, this vulnerability poses a severe risk to data integrity, confidentiality, and availability, as an attacker could gain full control over backup infrastructure, potentially leading to data destruction or unauthorized exfiltration.
Remediation
Immediate Action: Upgrade to the patched versions specified in the Dell security advisory DSA-2026-060, which include releases 8.6.1.10, 8.7.0.0, 8.3.1.30, 7.13.1.70, or 2.7.9.
Proactive Monitoring: Monitor system logs for unauthorized administrative activity or unexpected command execution patterns originating from standard user accounts.
Compensating Controls: Restrict network access to the Data Domain management interface to trusted administrative subnets and enforce strict user access controls to minimize the likelihood of an authenticated user inadvertently triggering the exploit.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
Due to the severity of the impact and the potential for full system takeover, administrators should prioritize applying the provided firmware and software updates immediately. Ensure that the patch cycle includes all affected PowerProtect Data Domain instances, and verify that administrative interfaces are not exposed to the public internet to further reduce the risk of exploitation.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank brocked200 (Nguyen Quoc Khanh) for reporting these issues., per the CVE Program record.