Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.
Published: 2026-07-03
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain firmware contains an incorrect authorization flaw (CWE‑863) that allows a high‑privileged local attacker to run arbitrary commands on the appliance, resulting in unauthorized command execution.

Affected Systems

Affected system: Dell PowerProtect Data Domain firmware – versions 7.7.1.0 through 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The CVSS score of 4.2 places the vulnerability in the low‑severity range, while the EPSS score of less than 1% indicates a very low likelihood that attackers will exploit it in the wild. The flaw requires local access with high‑privilege rights and is not listed in the CISA KEV catalog, so the overall risk is limited to users who maintain elevated local privileges on the appliance.

Generated by OpenCVE AI on August 4, 2026 at 07:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Dell PowerProtect Data Domain firmware security update (DSA‑2026‑278) from Dell’s support website to resolve the authorization flaw.
  • Re‑evaluate local user accounts and remove or reduce high‑privilege permissions for accounts that do not require full administrative access.
  • Restrict physical access to the appliance by securing its location and enforcing strict in‑person access controls.

Generated by OpenCVE AI on August 4, 2026 at 07:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Enabling Local Command Execution on Dell PowerProtect Data Domain

Sat, 25 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Authorization Flaw Enabling Local Command Execution on Dell PowerProtect Data Domain

Tue, 21 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw Enabling Command Execution on Dell PowerProtect Data Domain

Wed, 15 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw Enabling Command Execution on Dell PowerProtect Data Domain

Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local High‑Privileged Command Execution on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local High‑Privileged Command Execution on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw in Dell PowerProtect Data Domain Enables Unauthorized Command Execution

Fri, 10 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Authorization Flaw in Dell PowerProtect Data Domain Enables Unauthorized Command Execution

Thu, 09 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Unauthorized Command Execution on Dell PowerProtect Data Domain

Wed, 08 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Unauthorized Command Execution on Dell PowerProtect Data Domain

Wed, 08 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Unauthorized Command Execution via Incorrect Authorization

Mon, 06 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Unauthorized Command Execution via Incorrect Authorization

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allowing Unauthorized Command Execution on Dell PowerProtect Data Domain

Sun, 05 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allowing Unauthorized Command Execution on Dell PowerProtect Data Domain

Sun, 05 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local Unauthorized Command Execution in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows Local Unauthorized Command Execution in Dell PowerProtect Data Domain

Sat, 04 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Command Execution via Incorrect Authorization in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Command Execution via Incorrect Authorization in Dell PowerProtect Data Domain

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Fri, 03 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Dell Data Domain Operating System Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-07T13:12:20.640Z

Reserved: 2026-05-17T17:04:27.065Z

Link: CVE-2026-46730

cve-icon Vulnrichment

Updated: 2026-07-06T14:19:37.117Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-03T13:17:23.390

Modified: 2026-07-08T19:32:43.620

Link: CVE-2026-46730

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:00:03Z

Weaknesses