Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Published: 2026-07-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control within the RBAC system of Dell PowerProtect Data Domain allows a low‐privileged attacker with remote access to modify stored information, potentially leading to data integrity violations. The weakness is identified as CWE‑284.

Affected Systems

Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.6, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, whereas the EPSS score of < 1% reflects a very low likelihood of exploitation. The vulnerability requires remote access to the appliance's management interface and exploitation of the RBAC flaw, enabling unauthorized modifications.

Generated by OpenCVE AI on July 22, 2026 at 13:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell-provided security update DSA-2026-278 for PowerProtect Data Domain
  • Review and tighten RBAC role assignments to enforce least privilege for all users
  • Audit RBAC changes and monitor for unauthorized tampering attempts

Generated by OpenCVE AI on July 22, 2026 at 13:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Allows Data Tampering

Fri, 17 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Allows Data Tampering

Thu, 16 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Inadequate Access Control in Dell PowerProtect Data Domain Enables Low-Privileged Remote Information Tampering

Tue, 14 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Inadequate Access Control in Dell PowerProtect Data Domain Enables Low-Privileged Remote Information Tampering

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Enabling Low‑Privileged Data Tampering

Sat, 11 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Enabling Low‑Privileged Data Tampering

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC

Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Access Improper RBAC Allows Data Tampering in PowerProtect Data Domain

Wed, 08 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Access Improper RBAC Allows Data Tampering in PowerProtect Data Domain

Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain RBAC Improper Access Control Permits Remote Data Tampering

Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain RBAC Improper Access Control Permits Remote Data Tampering

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Enables Data Tampering on Dell PowerProtect

Mon, 06 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Enables Data Tampering on Dell PowerProtect

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper RBAC Access Control in Dell PowerProtect Data Domain Allows Information Tampering

Sun, 05 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Improper RBAC Access Control in Dell PowerProtect Data Domain Allows Information Tampering

Sun, 05 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Allows Data Tampering on Dell PowerProtect Data Domain

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Allows Data Tampering on Dell PowerProtect Data Domain

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Leading to Information Tampering

Fri, 03 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Leading to Information Tampering

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-06T16:27:44.306Z

Reserved: 2026-04-17T05:04:42.886Z

Link: CVE-2026-41123

cve-icon Vulnrichment

Updated: 2026-07-06T16:27:39.100Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses