Executive brief
Dell PowerProtect Data Manager is a backup and recovery solution used to protect enterprise data. A vulnerability in the Agent Service component could allow a user with low-level access to the local system to view sensitive information that should normally be restricted. This could lead to the exposure of configuration details or other internal data, though it does not directly allow for system takeover or data deletion.
Technical details
The Dell PowerProtect Agent Service (versions prior to 20.1) suffers from an incorrect permission assignment (CWE-732) for a critical resource. This vulnerability allows a local, authenticated attacker with low privileges to access resources that should be restricted to higher-privileged accounts or the system itself. Successful exploitation results in unauthorized information exposure. The issue is addressed in Dell PowerProtect Data Manager version 20.1.0.0 and later.
Affected products
- Dell PowerProtect Data Manager prior to 20.1.0.0
- Dell PowerProtect Agent Service prior to 20.1
Timeline
- 2026-04-01: advisory: Initial release of DSA-2026-158 by Dell
- 2026-04-08: disclosed: NVD publication date
- 2026-04-14: other: Last modified date for the Dell advisory