Description
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Published: 2026-09-03
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Data Manager versions 20.2.0.0 and earlier contain a server-side request forgery flaw in the REST API. An attacker with high privileges could exploit this SSRF to cause the system to make arbitrary outbound HTTP requests, enabling the attacker to read sensitive internal resources or data. This vulnerability can lead to the disclosure of confidential information.

Affected Systems

The affected product is Dell PowerProtect Data Manager. Versions 20.2.0.0 and all earlier releases are vulnerable. The vulnerability manifests in the API layer that handles administrative requests, and any deployment running these software versions is at risk.

Risk and Exploitability

The CVSS score of 4.1 indicates a moderate impact, but the exploit requires high privileges and a remote attacker can reach the vulnerable API. EPSS data is not available and the vulnerability is not listed in the KEV catalog, suggesting no known widespread exploitation yet. However, the SSRF weakness (CWE-918) can be leveraged in complex network environments, so systems should apply the Dell DSA-2026-368 update promptly.

Generated by OpenCVE AI on September 3, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Dell's DSA-2026-368 security update for PowerProtect Data Manager, which includes the SSRF patch.
  • Restrict the PowerProtect REST API to only allow connections to trusted IP addresses or block outbound networking except for necessary endpoints.
  • Place the PowerProtect service behind network segmentation or a firewall to limit the scope of a potential SSRF attack.

Generated by OpenCVE AI on September 3, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Title SSRF Vulnerability in Dell PowerProtect Data Manager REST API

Thu, 03 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Thu, 03 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-03T12:36:21.859Z

Reserved: 2026-08-16T11:04:50.573Z

Link: CVE-2026-74768

cve-icon Vulnrichment

Updated: 2026-09-03T12:36:13.588Z

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:07.307

Modified: 2026-09-03T13:06:07.307

Link: CVE-2026-74768

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:45:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)