Executive brief
Dell PowerProtect Data Manager, a solution for data backup and protection, contains a security vulnerability in its management interface. A high-privileged user could exploit this flaw to gain even higher levels of access or control over the system. This could lead to unauthorized access to sensitive backup data or full administrative control over the data management environment.
Technical details
An improper input validation vulnerability exists in the REST API of Dell PowerProtect Data Manager. A remote attacker with high privileges can exploit this flaw by sending specially crafted requests to the API. Successful exploitation allows the attacker to elevate their privileges within the system, potentially gaining full administrative control (Scope: Changed). The vulnerability is tracked as CVE-2026-40712 and has been addressed in version 20.2.0.0 and later.
Affected products
- Dell PowerProtect Data Manager prior to 20.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory