Description
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Published: 2026-07-07
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authentication flaw, classified as CWE‑287, allows an attacker with no credentials to bypass the PowerProtect Data Domain appliance’s login controls. This vulnerability can grant full privileged access to the system, enabling any operation normally restricted to authorized users and effectively providing remote takeover of the appliance.

Affected Systems

Dell PowerProtect Data Domain appliances running versions 7.7.1.0 through 8.7, LTS2026 releases 8.6.1.0 through 8.6.1.10, LTS2025 releases 8.3.1.0 through 8.3.1.30, and LTS2024 releases 7.13.1.0 through 7.13.1.70.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical, indicating the potential for full remote control. The EPSS score of less than 1% shows a very low but non‑zero likelihood of live exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits. The attack vector is likely an unauthenticated remote attacker sending a crafted request to the appliance’s authentication interface, which then grants elevated privileges.

Generated by OpenCVE AI on August 3, 2026 at 04:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Domain security update announced in Dell Support KB 000481268 as soon as possible
  • Restrict network access to the appliance’s management interface to trusted IP addresses until the patch is installed
  • Enable multi‑factor authentication for all management accounts and review authentication logs for suspicious activity

Generated by OpenCVE AI on August 3, 2026 at 04:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Dell PowerProtect Data Domain Allows Remote Access

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Improper Authentication in Dell PowerProtect Data Domain Allows Remote Access

Fri, 24 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Improper Authentication Enables Remote Takeover of Dell PowerProtect Data Domain

Tue, 21 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Improper Authentication Enables Remote Takeover of Dell PowerProtect Data Domain

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allowing Remote System Control

Wed, 15 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allowing Remote System Control

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper authentication allows full control of Dell PowerProtect Data Domain

Mon, 13 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper authentication allows full control of Dell PowerProtect Data Domain

Sun, 12 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allows Remote Control

Sat, 11 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Dell PowerProtect Data Domain Improper Authentication Allows Remote Control

Fri, 10 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass on Dell PowerProtect Data Domain

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Authentication Bypass on Dell PowerProtect Data Domain

Thu, 09 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Dell PowerProtect Data Domain

Wed, 08 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access Vulnerability in Dell PowerProtect Data Domain

Tue, 07 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Domain
Vendors & Products Dell
Dell powerprotect Data Domain

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Data Domain Operating System Powerprotect Data Domain
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-08T03:56:40.966Z

Reserved: 2026-06-09T17:04:35.250Z

Link: CVE-2026-53483

cve-icon Vulnrichment

Updated: 2026-07-07T13:40:22.378Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-07T13:16:31.590

Modified: 2026-07-08T19:57:04.163

Link: CVE-2026-53483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T05:00:16Z

Weaknesses