Description
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Published: 2026-08-26
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Script injection via symbolic‑link following that can lead to local command execution
Action: Apply patch
AI Analysis

Impact

Dell PowerProtect Cyber Recovery versions earlier than 20.3 contain a flaw where the system blindly follows Unix symbolic links during file operations (CWE-61). A local attacker with limited privileges can create or modify a symlink that points at an executable or script, causing the recovery service to execute it. This injection allows the attacker to run arbitrary code with the privileges of the affected component, potentially compromising the integrity of the storage environment.

Affected Systems

The vulnerability affects Dell PowerProtect Cyber Recovery, including its Power Protect Cyber Recovery product line. All installations running any version earlier than 20.3 are vulnerable. No other Dell software is listed as impacted.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity, reflecting that exploitation requires local, non‑privileged access and is confined to the affected system. The lack of an EPSS value and absence from the CISA KEV catalogue suggest limited public exploitation activity. The attack is likely to involve local file manipulation, as remote exploitation would require additional compromise to gain local access.

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Dell security update released for PowerProtect Cyber Recovery version 20.3 or later as documented in Dell’s advisory.
  • Configure the recovery service to disable following of symbolic links or restrict link resolution to a trusted directory to prevent unintended execution.
  • Set strict file permissions on directories accessed by the service so that users without appropriate rights cannot create or alter symlinks pointing at sensitive resources.

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell cyber Recovery
Dell powerprotect Cyber Recovery
Vendors & Products Dell
Dell cyber Recovery
Dell powerprotect Cyber Recovery

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Symbolic‑Link Following in Dell PowerProtect Cyber Recovery Enables Script Injection

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Cyber Recovery Powerprotect Cyber Recovery
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-27T15:21:36.311Z

Reserved: 2026-08-25T15:04:54.600Z

Link: CVE-2026-79939

cve-icon Vulnrichment

Updated: 2026-08-27T15:21:27.905Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-26T20:18:14.263

Modified: 2026-09-01T16:11:31.447

Link: CVE-2026-79939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:35Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following