Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Published: 2026-07-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper access control within the RBAC system of Dell PowerProtect Data Domain allows a low‑privileged attacker with remote access to modify stored information, potentially leading to data integrity violations. The weakness, identified as CWE‑284, enables an attacker to alter or delete records or configurations without proper authorization, thereby compromising the integrity of the data domain. This vulnerability is a form of privilege escalation that can be leveraged to tamper with data or system settings without the need for elevated credentials.

Affected Systems

Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.6, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are impacted by this vulnerability.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of <1% reflects a very low likelihood of exploitation. The vulnerability requires remote access and a low‑privileged account, making it unlikely to be targeted in the broadest sense but still a concern for environments where such accounts exist.

Generated by OpenCVE AI on August 3, 2026 at 05:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply DSA-2026-278 update to all affected PowerProtect Data Domain appliances.
  • Review and tighten RBAC role assignments to enforce least privilege for all users.
  • Audit RBAC changes and monitor for unauthorized modifications.

Generated by OpenCVE AI on August 3, 2026 at 05:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Allows Low‑Privileged Data Tampering

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Allows Low‑Privileged Data Tampering

Wed, 22 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Allows Data Tampering

Fri, 17 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Allows Data Tampering

Thu, 16 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Inadequate Access Control in Dell PowerProtect Data Domain Enables Low-Privileged Remote Information Tampering

Tue, 14 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Inadequate Access Control in Dell PowerProtect Data Domain Enables Low-Privileged Remote Information Tampering

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Enabling Low‑Privileged Data Tampering

Sat, 11 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC Enabling Low‑Privileged Data Tampering

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC

Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect Data Domain RBAC

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote Access Improper RBAC Allows Data Tampering in PowerProtect Data Domain

Wed, 08 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Access Improper RBAC Allows Data Tampering in PowerProtect Data Domain

Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain RBAC Improper Access Control Permits Remote Data Tampering

Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain RBAC Improper Access Control Permits Remote Data Tampering

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Enables Data Tampering on Dell PowerProtect

Mon, 06 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Enables Data Tampering on Dell PowerProtect

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper RBAC Access Control in Dell PowerProtect Data Domain Allows Information Tampering

Sun, 05 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Improper RBAC Access Control in Dell PowerProtect Data Domain Allows Information Tampering

Sun, 05 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Allows Data Tampering on Dell PowerProtect Data Domain

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in RBAC Allows Data Tampering on Dell PowerProtect Data Domain

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Leading to Information Tampering

Fri, 03 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Dell PowerProtect RBAC Leading to Information Tampering

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Dell Data Domain Operating System Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-06T16:27:44.306Z

Reserved: 2026-04-17T05:04:42.886Z

Link: CVE-2026-41123

cve-icon Vulnrichment

Updated: 2026-07-06T16:27:39.100Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T13:17:10.720

Modified: 2026-07-08T19:34:50.650

Link: CVE-2026-41123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:30:17Z

Weaknesses