Description
Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Published: 2026-08-26
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell PowerProtect Cyber Recovery versions earlier than 20.3 contain a flaw where the system blindly follows Unix symbolic links during file operations (CWE-61). A local attacker with limited privileges can create or modify a symlink that points at an executable or script, causing the recovery service to execute it. This injection allows the attacker to run arbitrary code with the privileges of the affected component, potentially compromising the integrity of the storage environment.

Affected Systems

The vulnerability affects Dell PowerProtect Cyber Recovery, including its Power Protect Cyber Recovery product line. All installations running any version earlier than 20.3 are vulnerable. No other Dell software is listed as impacted.

Risk and Exploitability

The CVSS score of 5.8 indicates moderate severity, reflecting that exploitation requires local, non‑privileged access and is confined to the affected system. The lack of an EPSS value and absence from the CISA KEV catalogue suggest limited public exploitation activity. The attack is likely to involve local file manipulation, as remote exploitation would require additional compromise to gain local access.

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Dell security update released for PowerProtect Cyber Recovery version 20.3 or later as documented in Dell’s advisory.
  • Configure the recovery service to disable following of symbolic links or restrict link resolution to a trusted directory to prevent unintended execution.
  • Set strict file permissions on directories accessed by the service so that users without appropriate rights cannot create or alter symlinks pointing at sensitive resources.

Generated by OpenCVE AI on August 26, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Symbolic‑Link Following in Dell PowerProtect Cyber Recovery Enables Script Injection

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
Weaknesses CWE-61
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-26T19:32:57.153Z

Reserved: 2026-08-25T15:04:54.600Z

Link: CVE-2026-79939

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T20:18:14.263

Modified: 2026-08-26T20:18:14.263

Link: CVE-2026-79939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T23:00:14Z

Weaknesses
  • CWE-61

    UNIX Symbolic Link (Symlink) Following