Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-07-03
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain has a path traversal vulnerability (CWE-22). A high-privileged local attacker may read files outside the designated restricted directory, potentially exposing sensitive information. The vulnerable code does not enforce proper path limiting, allowing traversal to parent directories that are not intended to be accessed.

Affected Systems

Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 are affected.

Risk and Exploitability

The EPSS score is <1%, indicating a very low likelihood of exploitation. The CVSS score of 2.3 classifies this as low severity and it is not listed in the CISA KEV catalog. Exploitation requires local access with high privileges; a remote attacker would first need to compromise a user with sufficient rights on the appliance.

Generated by OpenCVE AI on July 21, 2026 at 09:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update for PowerProtect Data Domain referenced in the Dell support advisory (https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities).
  • Limit local privileged access by enforcing least privilege and removing or disabling unnecessary local accounts on the Data Domain appliance.
  • Segment the Data Domain appliance network and configure firewall rules to restrict external access, reducing the attack surface for local compromises.

Generated by OpenCVE AI on July 21, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell PowerProtect Data Domain Enables Local Information Exposure

Thu, 16 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in Dell PowerProtect Data Domain Exposes Sensitive Information

Tue, 14 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal in Dell PowerProtect Data Domain Exposes Sensitive Information

Mon, 13 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Leading to Information Exposure on Dell PowerProtect Data Domain

Sun, 12 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Leading to Information Exposure on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability in Dell PowerProtect Data Domain

Fri, 10 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Leading to Information Exposure in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Leading to Information Exposure in Dell PowerProtect Data Domain

Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability Allows Information Exposure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability Allows Information Exposure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Causing Information Exposure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Causing Information Exposure in Dell PowerProtect Data Domain

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability in Dell PowerProtect Data Domain Allows Information Exposure

Sun, 05 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Vulnerability in Dell PowerProtect Data Domain Allows Information Exposure

Sat, 04 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Causing Information Exposure in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Path Traversal Causing Information Exposure in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-06T16:34:41.734Z

Reserved: 2026-04-17T05:04:42.886Z

Link: CVE-2026-41124

cve-icon Vulnrichment

Updated: 2026-07-06T16:34:38.132Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')