Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Published: 2026-07-03
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain has a flaw that causes sensitive information to be written into audit logs, a CWE‑532 vulnerability. The description does not mention any impact on data integrity or system availability, so the issue is limited to potential exposure of credentials, configuration details, or other private data stored in the logs.

Affected Systems

Affected releases include Dell PowerProtect Data Domain 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70. Any appliance running these versions in a local environment is vulnerable.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate risk level, and the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker with local access to trigger the logging mechanism, after which the attacker can read sensitive data from the log files, threatening confidentiality. The likely attack vector is local, and the direct impact is information disclosure.

Generated by OpenCVE AI on July 21, 2026 at 09:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s DSA‑2026‑278 security update to all affected PowerProtect Data Domain appliances.
  • Restrict local account privileges by enforcing least privilege for users capable of generating audit logs.
  • Configure audit logging to redact or exclude sensitive fields before writing to log files, reducing exposure risk.

Generated by OpenCVE AI on July 21, 2026 at 09:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged in Dell PowerProtect Data Domain

Thu, 16 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Log File Insertion in Dell PowerProtect Data Domain

Tue, 14 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Log File Insertion in Dell PowerProtect Data Domain

Mon, 13 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Log File Insertion in Dell PowerProtect Data Domain

Mon, 13 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Exposure via Log File Insertion in Dell PowerProtect Data Domain

Sat, 11 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged in Dell PowerProtect Data Domain Leading to Information Exposure

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged in Dell PowerProtect Data Domain Leading to Information Exposure

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Log File Sensitive Information Exposure in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Log File Sensitive Information Exposure in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Leaked via Log Files in PowerProtect Data Domain

Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Sensitive Information Leaked via Log Files in PowerProtect Data Domain

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Log Disclosure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Log Disclosure in Dell PowerProtect Data Domain

Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Sensitive Data Leakage via Log Files in Dell PowerProtect Data Domain

Sun, 05 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Sensitive Data Leakage via Log Files in Dell PowerProtect Data Domain

Sun, 05 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged to Log Files in Dell PowerProtect Data Domain

Sun, 05 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Sensitive Information Logged to Log Files in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Insertion into Log Files

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Insertion into Log Files

Sat, 04 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Log Injection Exposing Sensitive Information

Fri, 03 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Log Injection Exposing Sensitive Information

Fri, 03 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T02:14:33.621Z

Reserved: 2026-05-14T17:05:39.859Z

Link: CVE-2026-46467

cve-icon Vulnrichment

Updated: 2026-07-07T02:14:04.485Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:00:04Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File