Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Domain contains an improper limitation of a pathname to a restricted directory, a classic path traversal vulnerability (CWE-22). An unauthenticated attacker with remote access can forge a path that exits the intended filesystem boundaries, potentially accessing arbitrary files or directories on the appliance. The advisory states that successful exploitation may give the attacker complete control of the system, allowing them to read, modify, or delete data and to execute arbitrary commands, thereby breaching confidentiality, integrity, and availability.

Affected Systems

The affected devices are Dell PowerProtect Data Domain appliances. Vulnerable builds include software versions 7.7.1.0 through 8.7, the LTS2026 release series 8.6.1.0 to 8.6.1.10, the LTS2025 release series 8.3.1.0 to 8.3.1.30, and the LTS2024 release series 7.13.1.0 to 7.13.1.70.

Risk and Exploitability

The CVSS score of 9.8 marks the flaw as critical, while the EPSS score of less than 1% indicates a very low but non-zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Because authentication is not required, an attacker can reach the vulnerable functionality over the network and, after manipulating the pathname, gain unauthorized file access or administrative control, effectively compromising the entire appliance.

Generated by OpenCVE AI on July 24, 2026 at 09:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s security update DSA-2026-278, which patches the path traversal flaw across all affected versions.
  • Upgrade the appliance to a release version beyond the identified vulnerable ranges (e.g., 8.8 or later) to ensure the issue is fully resolved.
  • Restrict external network access to the PowerProtect services using firewalls or network segmentation until the update or upgrade has been completed.

Generated by OpenCVE AI on July 24, 2026 at 09:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploit in Dell PowerProtect Data Domain Allows Remote Full Control

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploit in Dell PowerProtect Data Domain Allows Remote Full Control

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Critical Path Traversal Vulnerability in Dell PowerProtect Data Domain

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Critical Path Traversal Vulnerability in Dell PowerProtect Data Domain

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Path Traversal in Dell PowerProtect Data Domain Enables System Compromise

Sun, 12 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Path Traversal in Dell PowerProtect Data Domain Enables System Compromise

Sat, 11 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell PowerProtect Data Domain Allows Remote Control

Fri, 10 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in Dell PowerProtect Data Domain Allows Remote Control

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Critical Path Traversal Vulnerability in Dell PowerProtect Data Domain

Thu, 09 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Critical Path Traversal Vulnerability in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Path Traversal in Dell PowerProtect Data Domain Enables Remote Control

Wed, 08 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Path Traversal in Dell PowerProtect Data Domain Enables Remote Control

Tue, 07 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T03:56:41.732Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53481

cve-icon Vulnrichment

Updated: 2026-07-07T13:21:12.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T09:30:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')