Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.
Published: 2026-07-07
Score: 7.2 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain appliances are vulnerable to an OS command injection flaw (CWE-78) stemming from improper neutralization of special elements in a command. The vulnerability allows a remote attacker with high‑privileged credentials to execute arbitrary commands with root privileges, effectively bypassing the appliance’s protection mechanisms and granting full control.

Affected Systems

All Dell PowerProtect Data Domain devices running firmware versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 to 8.6.1.10, LTS2025 releases 8.3.1.0 to 8.3.1.30, and LTS2024 releases 7.13.1.0 to 7.13.1.70 remain affected until a vendor‑issued patch is applied.

Risk and Exploitability

The CVSS base score of 7.2 classifies this flaw as high severity. The EPSS score of 1% indicates a low but non‑zero probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the vulnerability is exploitable remotely by an attacker who possesses high‑privileged access to the device. The risk will persist until the appliance is updated to a firmware version that resolves the command‑injection issue.

Generated by OpenCVE AI on July 26, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s security update by upgrading the appliance firmware to a version that fixes the command‑injection flaw
  • Restrict access to the appliance’s management interfaces to trusted networks only and disable remote management on untrusted hosts
  • Enforce strict authentication and role‑based access controls to prevent unauthorized privileged access, thereby limiting the potential impact of the vulnerability

Generated by OpenCVE AI on July 26, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection Enabling Remote Root Execution in Dell PowerProtect Data Domain

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerProtect Data Domain Allows Arbitrary Execution with Root Privileges

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerProtect Data Domain Allows Arbitrary Execution with Root Privileges

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation on Dell PowerProtect Data Domain

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation on Dell PowerProtect Data Domain

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation on Dell PowerProtect Data Domain

Mon, 13 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation on Dell PowerProtect Data Domain

Sat, 11 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation in Dell PowerProtect Data Domain

Fri, 10 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection Allowing Root Privilege Escalation in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerProtect Data Domain Allowing Ultimate Privilege Escalation

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell PowerProtect Data Domain Allowing Ultimate Privilege Escalation

Tue, 07 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Tue, 07 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T13:41:13.329Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53479

cve-icon Vulnrichment

Updated: 2026-07-08T13:41:10.322Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')