CVE-2026-68861

8.8

Dell · PowerProtect One

Dell PowerProtect One contains an OS Command Injection vulnerability that allows a low privileged, remote attacker to execute arbitrary commands on the affected system.

Executive summary

A critical OS Command Injection vulnerability in Dell PowerProtect One allows remote attackers with low-level privileges to achieve full remote code execution.

Vulnerability

This flaw is an OS Command Injection (CWE-78) vulnerability occurring in the application interface, which allows a remote attacker with low-level authentication to inject and execute arbitrary system commands.

Business impact

The ability for a low-privileged user to execute arbitrary commands on the system poses a severe risk to data confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to full system compromise, unauthorized data exfiltration, or the deployment of ransomware within the storage management environment.

Remediation

Immediate Action: Upgrade to Dell PowerProtect One version 20.3.0.0 or later as specified in the official vendor security advisory.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected shell commands originating from the web application service account.

Compensating Controls: Implement strict network segmentation to restrict access to the PowerProtect One management interface to authorized administrative segments only, and utilize a Web Application Firewall to filter malicious command patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a significant risk to the integrity of the Dell PowerProtect One environment. Security teams must prioritize applying the vendor-supplied update to version 20.3.0.0 immediately to eliminate the command injection vector and prevent potential unauthorized remote execution.

More Dell CVEs

Sources