Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-07-22
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper input validation flaw (CWE-20) that allows a remote attacker with high privileges to send crafted input to the REST API, potentially enabling elevation of privileges.

Affected Systems

Dell PowerProtect Data Manager versions prior to 20.2.0.0 are affected. The flaw exists within the REST API component of the product.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical level of severity for privilege escalation. The EPSS score of <1% shows a low probability of exploitation, and the vulnerability is not listed in CISA KEV. Exploitation requires remote network access to the REST API and high‑privileged accounts; if the API is exposed to potential adversaries, the flaw poses a system‑wide risk.

Generated by OpenCVE AI on August 3, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Dell PowerProtect Data Manager to version 20.2.0.0 or later as provided in Dell’s security update
  • Restrict REST API exposure to trusted IP ranges or internal networks using firewall or reverse proxy rules to limit access to high‑privilege users
  • Enforce least privilege for API accounts, removing unnecessary high‑privileged access and requiring multi‑factor authentication where possible

Generated by OpenCVE AI on August 3, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Privilege Escalation

Sun, 02 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enables Privilege Escalation

Thu, 30 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title REST API Improper Input Validation Leading to Privilege Escalation in Dell PowerProtect Data Manager

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title REST API Improper Input Validation Leading to Privilege Escalation in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-24T03:56:06.739Z

Reserved: 2026-04-15T05:04:31.837Z

Link: CVE-2026-40712

cve-icon Vulnrichment

Updated: 2026-07-23T15:42:57.913Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:19.247

Modified: 2026-07-29T17:40:59.493

Link: CVE-2026-40712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:05Z

Weaknesses
  • CWE-20

    Improper Input Validation