Description
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-07-22
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Manager contains a flaw that generates incorrect security tokens within its Identity and Access Management component. The weakness, classified as CWE-1270, is an authorization inadequacy that allows an attacker with low privileges to compel the system into assigning higher‑level privileges. This can lead to unauthorized actions, data exposure, and compromise of system integrity.

Affected Systems

The vulnerability affects Dell PowerProtect Data Manager versions earlier than 20.2.0.0. No other versions or products are reported as impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity rating. The EPSS score of < 1% suggests a low probability of exploitation, yet the risk remains because the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a low‑privileged attacker gaining remote access to an exposed endpoint of the IAM service and manipulating the token generation process to elevate privileges.

Generated by OpenCVE AI on August 4, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Manager security update referenced in DSA-2026-287
  • If a patch cannot be applied immediately, restrict remote access to the IAM service to trusted users only
  • Review and tighten user role definitions to limit low privileged accounts from performing critical IAM operations

Generated by OpenCVE AI on August 4, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Security Token Generation in Dell PowerProtect Data Manager

Sun, 02 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Security Token Generation in Dell PowerProtect Data Manager

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Incorrect Security Tokens Allowing Privilege Escalation in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Incorrect Security Tokens Allowing Privilege Escalation in Dell PowerProtect Data Manager

Thu, 23 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-1270
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-24T03:56:08.365Z

Reserved: 2026-05-31T17:04:24.517Z

Link: CVE-2026-49499

cve-icon Vulnrichment

Updated: 2026-07-22T16:22:58.974Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T16:17:29.943

Modified: 2026-07-29T17:37:24.533

Link: CVE-2026-49499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-1270

    Generation of Incorrect Security Tokens