Description
Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-08-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Immediately
AI Analysis

Impact

Dell PowerProtect Cyber Recovery, versions 20.2 and earlier, have a SQL injection flaw classified as Improper Neutralization of Special Elements used in an SQL Command (CWE-89). The flaw allows an attacker with low privileges and remote access to supply malicious input that is incorporated into database queries, potentially exposing sensitive data stored in the backend. This type of vulnerability can lead to the compromise of confidential information without affecting system availability or integrity directly.

Affected Systems

The affected products are Dell PowerProtect Cyber Recovery and Dell Cyber Recovery. The vulnerability exists in all releases version 20.2 and older, including all earlier patch levels of these products.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, reflecting the possibility of data exposure. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access and a low privileged user account; therefore, the likely vector is a remote network connection. Once exploited, the attacker could retrieve data from the database, but the vulnerability does not provide direct code execution or denial of service capabilities.

Generated by OpenCVE AI on August 26, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Cyber Recovery security update that addresses the SQL injection flaw.
  • Restrict remote management access to trusted network segments or enforce multi‑factor authentication so that only highly privileged users can connect to the vulnerable services.
  • Implement continuous monitoring of database logs for suspicious query patterns and configure alerts for anomalous access attempts.

Generated by OpenCVE AI on August 26, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell cyber Recovery
Dell powerprotect Cyber Recovery
Vendors & Products Dell
Dell cyber Recovery
Dell powerprotect Cyber Recovery

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in Dell PowerProtect Cyber Recovery Allowing Information Disclosure

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Dell Cyber Recovery Powerprotect Cyber Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-28T18:35:57.350Z

Reserved: 2026-06-01T17:04:30.333Z

Link: CVE-2026-49809

cve-icon Vulnrichment

Updated: 2026-08-28T18:30:12.878Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-26T20:17:52.440

Modified: 2026-09-02T15:09:18.040

Link: CVE-2026-49809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:36Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')