Description
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Cyber Recovery, versions 20.2 and earlier, have a SQL injection flaw classified as Improper Neutralization of Special Elements used in an SQL Command (CWE-89). The flaw allows an attacker with low privileges and remote access to supply malicious input that is incorporated into database queries, potentially exposing sensitive data stored in the backend. This type of vulnerability can lead to the compromise of confidential information without affecting system availability or integrity directly.

Affected Systems

The affected products are Dell PowerProtect Cyber Recovery and Dell Cyber Recovery. The vulnerability exists in all releases version 20.2 and older, including all earlier patch levels of these products.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, reflecting the possibility of data exposure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access and a low privileged user account; therefore, the likely vector is a remote network connection. Once exploited, the attacker could retrieve data from the database, but the vulnerability does not provide direct code execution or denial of service capabilities.

Generated by OpenCVE AI on August 26, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Cyber Recovery security update that addresses the SQL injection flaw.
  • Restrict remote management access to trusted network segments or enforce multi‑factor authentication so that only highly privileged users can connect to the vulnerable services.
  • Implement continuous monitoring of database logs for suspicious query patterns and configure alerts for anomalous access attempts.

Generated by OpenCVE AI on August 26, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell PowerProtect Cyber Recovery Allowing Information Disclosure

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:28:34.851Z

Reserved: 2026-06-01T17:04:30.333Z

Link: CVE-2026-49809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:52.440

Modified: 2026-08-26T20:17:52.440

Link: CVE-2026-49809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')