Description
Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-08-26
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Cyber Recovery versions before 20.3 contain an Improper Authentication flaw that permits a low‑privileged attacker with remote access to bypass authentication controls and gain unauthorized access to protected resources.

Affected Systems

The vulnerability affects Dell PowerProtect Cyber Recovery systems deployed by Dell’s Cyber Recovery and Power Protect Cyber Recovery lines, specifically all releases prior to version 20.3.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high severity, although no EPSS score is available and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is remote, and the attacker only needs low privileges on the network to attempt the exploit, making it exploitable from a wide range of threat actor capabilities.

Generated by OpenCVE AI on August 26, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Dell PowerProtect Cyber Recovery update (version 20.3 or later) to eliminate the authentication bypass flaw.
  • If an immediate update is not feasible, restrict remote access to the affected components using firewalls or network segmentation to limit attacker proximity.
  • Continuously monitor authentication logs for anomalous or repeated failed login attempts that may indicate exploitation attempts.

Generated by OpenCVE AI on August 26, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Improper Authentication Allows Unauthorized Access in Dell PowerProtect Cyber Recovery

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:37:36.076Z

Reserved: 2026-08-25T15:04:54.600Z

Link: CVE-2026-79938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T20:18:14.140

Modified: 2026-08-26T20:18:14.140

Link: CVE-2026-79938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses