Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
Published: 2026-07-03
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain suffers from an improper link resolution before file access, also known as link following. During file access operations the system follows symbolic or relative links without adequate validation, potentially exposing internal files to an attacker. This flaw corresponds to CWE‑59 and, if a high‑privilege attacker has remote access, could lead to information disclosure.

Affected Systems

Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, the LTS2026 release versions 8.6.1.0 through 8.6.1.10, the LTS2025 release versions 8.3.1.0 through 8.3.1.30, and the LTS2024 release versions 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.9, reflecting moderate severity. The EPSS score of <1% indicates a low likelihood that this flaw will be actively exploited. It is not listed in the CISA KEV catalog. Exploitation requires a high‑privilege attacker who already has remote access, after which the improper link resolution can expose internal files and lead to information disclosure.

Generated by OpenCVE AI on July 23, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the DSA-2026-278 update to all affected PowerProtect Data Domain appliances
  • Enable detailed file‑access logging and monitor for abnormal link‑following to isolate administrative interfaces from public networks
  • Regularly check Dell’s official website for security advisories and apply updates promptly

Generated by OpenCVE AI on July 23, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution in Dell PowerProtect Data Domain Vulnerability

Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution in Dell PowerProtect Data Domain Vulnerability

Tue, 14 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Enables Conditional Information Data Domain

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Enables Conditional Information Data Domain

Sun, 12 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Leading to Information Disclosure in Dell PowerProtect Data Domain

Sat, 11 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Leading to Information Disclosure in Dell PowerProtect Data Domain

Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper link resolution before file access in Dell PowerProtect Data Domain leading to information disclosure

Thu, 09 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Improper link resolution before file access in Dell PowerProtect Data Domain leading to information disclosure

Thu, 09 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Before File Access Allows Remote Information Disclosure on Dell PowerProtect Data Domain

Wed, 08 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Before File Access Allows Remote Information Disclosure on Dell PowerProtect Data Domain

Tue, 07 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Allowing Information Disclosure in Dell PowerProtect Data Domain

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Allowing Information Disclosure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Vulnerability Allows High‑Privilege Remote Attacker to Read Sensitive Files

Sun, 05 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Vulnerability Allows High‑Privilege Remote Attacker to Read Sensitive Files

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Allows Remote Information Disclosure in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Improper Link Resolution Allows Remote Information Disclosure in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Link Resolution Leading to Information Disclosure

Sat, 04 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Link Resolution Leading to Information Disclosure

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T02:15:08.108Z

Reserved: 2026-05-14T17:05:39.859Z

Link: CVE-2026-46464

cve-icon Vulnrichment

Updated: 2026-07-07T02:15:03.127Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T16:30:09Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')