Description
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Published: 2026-08-26
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Cloud Disaster Recovery 20.2 and earlier contain an OS Command Injection flaw that allows an attacker with high privileges and remote access to inject arbitrary operating system commands. The deficiency stems from improper neutralization of special elements used in a system command, which could let the attacker execute arbitrary code and compromise the confidentiality, integrity, and availability of the affected deployment.

Affected Systems

Dell Cloud Disaster Recovery 20.2 and all earlier releases are impacted. The vulnerability applies to the entire product where remote management interfaces are exposed.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity of the flaw. The EPSS score is not available, so the exploitation probability cannot be quantified from that metric. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a remote attacker with sufficient privileges who can access the management interface, potentially exploiting the flaw over the network. Exploitation would grant the attacker complete command execution capabilities on the underlying host.

Generated by OpenCVE AI on August 26, 2026 at 19:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell security update for Cloud Disaster Recovery as documented in the Dell advisory.
  • Restrict remote management access to the service by using VPNs or trusted network segments.
  • Restrict or remove command execution privileges for non‑administrative users and disable any unnecessary command‑execution functionality.

Generated by OpenCVE AI on August 26, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Dell Cloud Disaster Recovery 20.2 and Earlier
First Time appeared Dell
Dell cloud Disaster Recovery
Vendors & Products Dell
Dell cloud Disaster Recovery

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Cloud Disaster Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T18:52:08.264Z

Reserved: 2026-08-04T11:16:10.499Z

Link: CVE-2026-70419

cve-icon Vulnrichment

Updated: 2026-08-26T18:52:00.071Z

cve-icon NVD

Status : Received

Published: 2026-08-26T19:16:56.540

Modified: 2026-08-26T20:17:58.077

Link: CVE-2026-70419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')