CVE-2026-68861
8.8Dell · PowerProtect One
Dell PowerProtect One contains an OS Command Injection vulnerability that allows a low privileged, remote attacker to execute arbitrary commands on the affected system.
Executive summary
A critical OS Command Injection vulnerability in Dell PowerProtect One allows remote attackers with low-level privileges to achieve full remote code execution.
Vulnerability
This flaw is an OS Command Injection (CWE-78) vulnerability occurring in the application interface, which allows a remote attacker with low-level authentication to inject and execute arbitrary system commands.
Business impact
The ability for a low-privileged user to execute arbitrary commands on the system poses a severe risk to data confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to full system compromise, unauthorized data exfiltration, or the deployment of ransomware within the storage management environment.
Remediation
Immediate Action: Upgrade to Dell PowerProtect One version 20.3.0.0 or later as specified in the official vendor security advisory.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected shell commands originating from the web application service account.
Compensating Controls: Implement strict network segmentation to restrict access to the PowerProtect One management interface to authorized administrative segments only, and utilize a Web Application Firewall to filter malicious command patterns.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability presents a significant risk to the integrity of the Dell PowerProtect One environment. Security teams must prioritize applying the vendor-supplied update to version 20.3.0.0 immediately to eliminate the command injection vector and prevent potential unauthorized remote execution.