Description
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-08-26
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an OS Command Injection flaw (CWE‑78) in the REST API of Dell Cloud Disaster Recovery, rated with a CVSS score of 7.2 – indicating a high severity problem. An attacker with sufficient privileges who can reach the exposed API can inject arbitrary operating‑system commands and execute them, leading to remote code execution on the affected server. The description states that a high‑privileged attacker with remote access could potentially exploit the flaw, and the risk materializes as the possibility of insider or compromised admin credentials.

Affected Systems

Dell Cloud Disaster Recovery versions 20.2 and all older releases are vulnerable. The flaw exists in the REST API surface that becomes available when the product is deployed, and it can be triggered on any affected installation that exposes the API to a network path, whether within a corporate LAN or over a public endpoint.

Risk and Exploitability

The CVSS of 7.2 reflects the confluence of high impact (remote execution) and the need for high‑privileged credentials. EPSS data is not available, yet the requirement for elevated access and remote API exposure limits the attacker pool to individuals with prior compromise or privileged accounts. Based on the description that a high privileged attacker is required, it is inferred that valid credentials with sufficient privileges are needed for exploitation. Because the flaw is not listed in the CISA KEV catalog, there are no known widespread exploits yet, but the high severity rating and remote nature of the attack vector justify immediate mitigation actions.

Generated by OpenCVE AI on August 26, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑353 security update for Cloud Disaster Recovery
  • Upgrade to a version newer than 20.2 that removes the vulnerability
  • Restrict the REST API to trusted administrators or networks until the update is applied

Generated by OpenCVE AI on August 26, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell cloud Disaster Recovery
Vendors & Products Dell
Dell cloud Disaster Recovery

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Cloud Disaster Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T18:48:27.558Z

Reserved: 2026-08-04T23:04:32.436Z

Link: CVE-2026-71171

cve-icon Vulnrichment

Updated: 2026-08-26T18:48:22.783Z

cve-icon NVD

Status : Received

Published: 2026-08-26T19:16:57.647

Modified: 2026-08-26T20:17:59.020

Link: CVE-2026-71171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')