Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-07-22
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Manager versions earlier than 20.2.0.0 contain an improper input validation weakness in the REST API, allowing a remote attacker who already has high‑privileged credentials to supply crafted parameters that the system accepts without adequate checks. This flaw can be leveraged to obtain higher privileges within the appliance, potentially granting full administrative control. The weakness is identified as CWE‑20: Improper Input Validation.

Affected Systems

All Dell PowerProtect Data Manager appliances running software revision 20.2.0.0 or earlier are affected. The vulnerability targets the REST API interface exposed by the appliance, meaning any system running the vulnerable version is exposed until a patch or upgrade is applied.

Risk and Exploitability

The CVSS base score of 9.1 marks this issue as critical, and the EPSS score of less than 1% indicates a very low overall likelihood of exploitation in the wild, though targeted attacks could still occur. Because the flaw is accessed remotely via the REST API and requires high‑privileged credentials, the attack surface remains limited to those with legitimate administrative access. While the vulnerability is not yet listed in the CISA KEV catalog, it poses a significant risk to affected enterprises, especially if their API endpoints are reachable from untrusted networks.

Generated by OpenCVE AI on August 3, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell PowerProtect Data Manager patch or upgrade to version 20.2.0.0 or later
  • Restrict network access to the REST API to trusted hosts and administrators only
  • Ensure that the REST API traffic is protected by TLS and requires strong authentication

Generated by OpenCVE AI on August 3, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enabling Privilege Escalation

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Enabling Privilege Escalation

Tue, 28 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Leading to Privilege Escalation

Sun, 26 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Dell PowerProtect Data Manager REST API Leading to Privilege Escalation

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-24T03:56:07.554Z

Reserved: 2026-05-17T17:04:27.066Z

Link: CVE-2026-46738

cve-icon Vulnrichment

Updated: 2026-07-23T13:50:22.532Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:24.223

Modified: 2026-07-29T17:39:21.237

Link: CVE-2026-46738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:05Z

Weaknesses
  • CWE-20

    Improper Input Validation