Description
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-08-26
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect One versions 20.1.0.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command vulnerability. This flaw can allow instructions supplied by a low privileged attacker with remote access to be executed directly on the host operating system. If successfully exploited, the attacker could run arbitrary commands with the privileges of the affected service, potentially compromising confidentiality, integrity, and availability of the entire storage system.

Affected Systems

The vulnerability impacts Dell PowerProtect One products, specifically versions 20.1.0.0 and all lower releases. All deployments using these versions are vulnerable until the security update is applied.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high severity flaw. The EPSS score is not available, but the vulnerability is not currently listed in CISA’s KEV catalog, suggesting it may not yet have active public exploitation. However, the flaw permits remote command execution and is exploitable by attackers who have remote access, making the risk significant for exposed or remotely reachable installations.

Generated by OpenCVE AI on August 26, 2026 at 20:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell’s latest PowerProtect One security update available from Dell Support
  • Restrict remote management access to trusted networks or IP ranges via firewall rules
  • Configure the product to run with the least privilege required and disable any unnecessary remote management interfaces

Generated by OpenCVE AI on August 26, 2026 at 20:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title PowerProtect One OS Command Injection Vulnerability Allowing Remote Execution

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T18:54:30.310Z

Reserved: 2026-07-31T17:04:55.170Z

Link: CVE-2026-68861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:57.710

Modified: 2026-08-26T20:17:57.710

Link: CVE-2026-68861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:45:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')