Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Published: 2026-07-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw in the web interface of Dell PowerProtect Data Domain. It allows an attacker to inject malicious script content that is saved by the system and executed automatically whenever a legitimate user accesses a page that displays the injected data. Once executed in the victim’s browser, the script can read sensitive information exposed in the page context, hijack session cookies, or trigger client‑side HTTP requests on behalf of the user, thereby enabling information disclosure, session theft, or client‑side request forgery.

Affected Systems

Dell PowerProtect Data Domain systems running firmware versions 7.7.1.0 through 8.7, the LTS2026 release 8.6.1.0 through 8.6.1.10, the LTS2025 release 8.3.1.0 through 8.3.1.30, and the LTS2024 release 7.13.1.0 through 7.13.1.70 are affected. The attackers need only unauthenticated remote access to the web interface; no special configuration changes or privileged accounts are required.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not recorded in the CISA KEV catalog. An unauthenticated attacker who can reach the Data Domain web interface can submit a crafted request containing the malicious script, which the system stores and serves to legitimate users. Upon viewing the affected page, any user’s browser will run the injected code, leading to the potential impacts described above.

Generated by OpenCVE AI on July 28, 2026 at 09:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply Dell’s security update that addresses the XSS flaw, as described in the Dell advisory.
  • Restrict external access to the Data Domain web interface by configuring firewall policies or network segmentation so that only trusted IP addresses or subnets can reach the interface.
  • Continuously monitor web‑application logs and user session activity for indicators of XSS exploitation, such as unexpected client‑side requests or anomalous JavaScript execution.

Generated by OpenCVE AI on July 28, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Stored XSS in Dell PowerProtect Data Domain Web Interface

Thu, 23 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Stored XSS in Dell PowerProtect Data Domain Web Interface

Tue, 21 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Wed, 15 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Sun, 12 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Sat, 11 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain Web Interface

Fri, 10 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting Vulnerability in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T14:25:18.019Z

Reserved: 2026-04-17T05:04:42.886Z

Link: CVE-2026-41122

cve-icon Vulnrichment

Updated: 2026-07-08T14:25:14.611Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')