Description
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Published: 2026-09-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user with low privileges can exploit an incorrect authorization flaw in the REST API of Dell PowerProtect Data Manager. The vulnerability, identified as CWE‑863, allows an attacker to bypass configured protection mechanisms, potentially leading to unauthorized data access or manipulation.

Affected Systems

Dell PowerProtect Data Manager software, specifically versions 20.2.0.0 and earlier, are affected by this issue.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The absence of an EPSS score and the fact that it is not listed in the CISA KEV catalog suggest that the likelihood of exploitation is currently uncertain, though not zero. The attack vector is likely remote over the exposed REST API; a low‑privileged user could craft requests that circumvent normal access checks to achieve privilege escalation and bypass protection controls.

Generated by OpenCVE AI on September 3, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect Data Manager security update released in August 2026 (DSA‑2026‑368).
  • Restrict network access to the REST API, allowing connections only from trusted hosts or using VPNs.
  • Enforce multi‑factor authentication or stronger access controls on all API endpoints to mitigate incorrect authorization.

Generated by OpenCVE AI on September 3, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization in PowerProtect Data Manager REST API Allows Protection Mechanism Bypass
First Time appeared Dell
Dell powerprotect Data Manager
Vendors & Products Dell
Dell powerprotect Data Manager

Thu, 03 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Dell Powerprotect Data Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-03T08:10:48.667Z

Reserved: 2026-08-16T11:04:50.574Z

Link: CVE-2026-74769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T13:06:07.447

Modified: 2026-09-03T13:06:07.447

Link: CVE-2026-74769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:30:04Z

Weaknesses