Description
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Published: 2026-08-26
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Authorization Bypass Through User-Controlled Key that allows a low‑privileged attacker with remote access to alter data stored by Dell PowerProtect One. This flaw is a CWE‑639 weakness in authorization mechanisms and could lead to unauthorized modification of backup data.

Affected Systems

Dell PowerProtect One, versions 20.1.0.0 and earlier, are affected. The flaw can be exercised by an attacker with local privileges on a remote‑connected system that manages the backup service.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity and the EPSS score is not available, so no estimation of exploitation probability can be made. The vulnerability is not listed in CISA KEV, suggesting it has not yet been widely observed in the wild. Attack requires remote access and low privilege, making it accessible to anyone who can reach the PowerProtect One management interface. Mitigation is urgent to prevent potential tampering of backup data.

Generated by OpenCVE AI on August 26, 2026 at 20:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell PowerProtect One security update referenced in Dell DSA 2026‑369 (upgrade to a version newer than 20.1.0.0).
  • Limit remote management access to trusted networks and enforce least‑privilege permissions for all users.
  • Configure and monitor audit logs for unusual key usage or data modification events.

Generated by OpenCVE AI on August 26, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via User‑Controlled Key Allowing Backup Data Tampering

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:11:48.631Z

Reserved: 2026-08-16T11:04:50.574Z

Link: CVE-2026-74771

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T20:17:59.480

Modified: 2026-08-26T20:17:59.480

Link: CVE-2026-74771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:00:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key