Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2026-07-22
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Exposure of Sensitive Information to an Unauthorized Actor in the REST API of Dell PowerProtect Data Manager. A high privileged attacker with local access could exploit this flaw, resulting in the unauthorized disclosure of potentially sensitive data. The weakness is classified as CWE-200, a classic information‑leak scenario.

Affected Systems

Dell PowerProtect Data Manager versions prior to 20.2.0 The REST API in those releases can leak sensitive information to attackers who possess local high‑privileged access.

Risk and Exploitability

The CVSS score of 6 indicates moderate severity, and the EPSS score is 0.00108, indicating a very low exploitation probability. The vulnerability is not listed in CISA KEV, implying it is not a known exploited vulnerability at this time. The attack vector is local with high privilege, meaning that any user who can act as a local high‑privileged user has the potential to trigger the information disclosure.

Generated by OpenCVE AI on August 3, 2026 at 23:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Manager 20.2.0.0 or later update that fixes the REST API exposure flaw.
  • Restrict local access to highly privileged accounts and enforce strict role‑based authentication for the REST API.
  • Review API configurations to ensure sensitive data is not exposed, and apply the least‑privilege principle to API access controls.

Generated by OpenCVE AI on August 3, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure in PowerProtect Data Manager REST API

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure in PowerProtect Data Manager REST API

Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title REST API Exposure of Sensitive Information in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title REST API Exposure of Sensitive Information in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-22T15:55:09.983Z

Reserved: 2026-05-05T17:04:45.714Z

Link: CVE-2026-44276

cve-icon Vulnrichment

Updated: 2026-07-22T15:55:06.704Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:22.593

Modified: 2026-07-29T17:40:07.540

Link: CVE-2026-44276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor