Executive brief
Dell PowerProtect Data Domain is a specialized storage appliance used for enterprise data backup, recovery, and deduplication. A vulnerability in its privilege management could allow an already high-privileged user to bypass certain restrictions and perform unauthorized data deletions. This could lead to the permanent loss of critical backup data or disruption of disaster recovery operations.
Technical details
Dell PowerProtect Data Domain appliances are affected by an improper privilege management vulnerability (CWE-269). The flaw exists in how the system handles permissions for administrative actions, specifically within the Integrated Dell Remote Access Controller (iDRAC) component according to some advisory versions. A high-privileged attacker with local access to the appliance could exploit this vulnerability to elevate their privileges further, enabling them to execute unauthorized delete operations that should otherwise be restricted. Exploitation may require user interaction or specific environmental conditions (AC:H/UI:R). Dell has released security updates to address this issue across affected LTS and feature release branches.
Affected products
- Dell PowerProtect Data Domain Operating System 7.7.1.0 through 8.7.0.0, 8.3.1.0 through 8.3.1.20 (LTS2025), 7.13.1.0 through 7.13.1.60 (LTS2024)
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory