Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.
Published: 2026-07-03
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain firmware contains an authorization flaw (CWE‑863) that lets a high‑privileged local attacker run arbitrary commands on the appliance, enabling unauthorized command execution.

Affected Systems

Affected system: Dell PowerProtect Data Domain firmware – versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The CVSS score of 4.2 places the vulnerability in the low‑severity range and the EPSS score of <1% indicates a very low probability of exploitation. The flaw requires local access with high‑privilege rights and is not listed in the CISA KEV catalog. Consequently, the risk is confined to users who maintain elevated local privileges on the appliance.

Generated by OpenCVE AI on July 21, 2026 at 09:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell PowerProtect Data Domain security patch DSA‑2026‑278 to fix the incorrect authorization flaw.
  • Upgrade the firmware to a non‑affected version beyond 8.7, or a newer LTS release.
  • Restrict local high‑privileged accounts to those strictly required for system operation.

Generated by OpenCVE AI on July 21, 2026 at 09:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw Enabling Command Execution on Dell PowerProtect Data Domain

Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw Enabling Command Execution on Dell PowerProtect Data Domain

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local High‑Privileged Command Execution on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local High‑Privileged Command Execution on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw in Dell PowerProtect Data Domain Enables Unauthorized Command Execution

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw in Dell PowerProtect Data Domain Enables Unauthorized Command Execution

Thu, 09 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Unauthorized Command Execution on Dell PowerProtect Data Domain

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Unauthorized Command Execution on Dell PowerProtect Data Domain

Wed, 08 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Unauthorized Command Execution via Incorrect Authorization

Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Unauthorized Command Execution via Incorrect Authorization

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allowing Unauthorized Command Execution on Dell PowerProtect Data Domain

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allowing Unauthorized Command Execution on Dell PowerProtect Data Domain

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local Unauthorized Command Execution in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local Unauthorized Command Execution in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Command Execution via Incorrect Authorization in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Command Execution via Incorrect Authorization in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T13:12:20.640Z

Reserved: 2026-05-17T17:04:27.065Z

Link: CVE-2026-46730

cve-icon Vulnrichment

Updated: 2026-07-06T14:19:37.117Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:00:04Z

Weaknesses