Junglewise Threat Intelligence

CVE-2026-26355: Dell PowerProtect Data Domain OS command injection

CVE-2026-26355 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security vulnerability has been identified that could allow a user with high-level administrative privileges to execute unauthorized operating system commands remotely. While this requires existing administrative access, an exploit could allow an attacker to bypass intended restrictions or disrupt system operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in operating system commands. The vulnerability affects multiple versions including the 7.7.1.0 through 8.7 range and various LTS releases (2024, 2025, 2026). An attacker with high privileges and network access can exploit this flaw to achieve arbitrary command execution on the underlying system. Dell has released security updates to address this issue, with fixed versions including 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed: Initial publication of the CVE record
  • 2026-07-03: advisory: Dell security advisory DSA-2026-278 published

References

Related threats