Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification.
Published: 2026-07-08
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This CVE reveals an improper limitation of a pathname to a restricted directory on Dell PowerProtect Data Domain appliances, a classic path‑traversal flaw. An attacker with high privileges and remote access can craft file paths that escape the intended directory and overwrite or modify existing files. The resulting confidentiality or integrity compromise depends on the targeted files, but the flaw can affect critical system files and configuration data.

Affected Systems

Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, including LTS2026 release versions 8.6.1.0 to 8.6.1.10, LTS2025 release versions 8.3.1.0 to 8.3.1.30, and LTS2024 release versions 7.13.1.0 to 7.13.1.70 are impacted.

Risk and Exploitability

The CVSS score of 2.7 reflects low overall risk, and the EPSS score of less than 1 % indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. While exploitation requires remote access and elevated privileges, which limits potential spread, any successful attack would enable an attacker to alter essential files on the appliance.

Generated by OpenCVE AI on July 28, 2026 at 09:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell PowerProtect Data Domain security update DSA‑2026‑278 to all affected versions
  • Implement strict path validation on all user-supplied file paths to prevent traversal (addressing CWE‑22)
  • Restrict remote access to the appliance and remove or limit high‑privilege user accounts
  • Ensure filesystem permissions and application path restrictions are enforced to prevent unauthorized file modifications

Generated by OpenCVE AI on July 28, 2026 at 09:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Leading to Unauthorized File Modification on Dell PowerProtect Data Domain

Fri, 24 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Pathname Limitation Leading to Unauthorized File Modification on Dell PowerProtect Data Domain

Tue, 21 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Pathname Limitation Leading to Unauthorized File Modification on Dell PowerProtect Data Domain

Thu, 16 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Multiple path traversal vulnerabilities in Dell PowerProtect Data Domain allow remote privileged file modification

Wed, 15 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Multiple path traversal vulnerabilities in Dell PowerProtect Data Domain allow remote privileged file modification

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Leading to Unauthorized File Modification in Dell PowerProtect Data Domain

Sun, 12 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Leading to Unauthorized File Modification in Dell PowerProtect Data Domain

Sat, 11 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Enabling Unauthorized File Modification

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Enabling Unauthorized File Modification

Fri, 10 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Enabling Unauthorized File Modification in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability Enabling Unauthorized File Modification in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Wed, 08 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T14:29:57.118Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53480

cve-icon Vulnrichment

Updated: 2026-07-08T14:29:26.815Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')