Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Published: 2026-07-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the Dell PowerProtect Data Domain web interface. An attacker can craft input containing malicious JavaScript that the system saves and later serves to legitimate users. When a victim accesses a page displaying the injected data, the script executes in the user’s browser, allowing the attacker to read sensitive information, hijack session cookies, or make HTTP requests on the user’s behalf, leading to information disclosure, session theft, or client‑side request forgery.

Affected Systems

Dell PowerProtect Data Domain firmware versions 7.7.1.0 through 8.7, LTS2026 release 8.6.1.0 through 8.6.1.10, LTS2025 release 8.3.1.0 through 8.3.1.30, and LTS2024 release 7.13.1.0 through 7.13.1.70 are affected. An unauthenticated attacker with remote access to the web interface can exploit the flaw; no special configuration changes or privileged accounts are required, as inferred from the description.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. An attacker can submit a crafted request containing malicious script, which the system stores and serves to legitimate users. Upon viewing the affected page, any user’s browser will run the injected code, leading to the potential impacts described above. Based on the description, it is inferred that no special configuration or privileged accounts are needed to exploit this vulnerability.

Generated by OpenCVE AI on August 3, 2026 at 04:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install Dell’s security update that resolves the XSS flaw, as detailed in the Dell advisory.
  • Restrict external access to the Data Domain web interface by configuring firewall rules or network segmentation to allow only trusted IP addresses or subnets.
  • Continuously monitor web‑application logs and user sessions for indicators of XSS exploitation, such as unusual client‑side requests or anomalous JavaScript execution.

Generated by OpenCVE AI on August 3, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting in Dell PowerProtect Data Domain Web Interface

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Stored XSS in Dell PowerProtect Data Domain Web Interface

Thu, 23 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Stored XSS in Dell PowerProtect Data Domain Web Interface

Tue, 21 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Wed, 15 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Sun, 12 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Fri, 10 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Dell Data Domain Operating System Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T14:25:18.019Z

Reserved: 2026-04-17T05:04:42.886Z

Link: CVE-2026-41122

cve-icon Vulnrichment

Updated: 2026-07-08T14:25:14.611Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-08T14:16:58.197

Modified: 2026-07-08T20:09:50.337

Link: CVE-2026-41122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:00:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')