Junglewise Threat Intelligence

CVE-2026-40714: Dell PowerProtect Data Manager privilege escalation via improper input validation

CVE-2026-40714 · Severity: high · CVSS 7.2 · Published 2026-07-22

Technologies: Dell Powerprotect Data Manager. Vendors: Dell.

Executive brief

Dell PowerProtect Data Manager, a platform used for enterprise data backup and protection, is vulnerable to a security flaw that allows for the elevation of privileges. A high-privileged attacker with network access could exploit this to gain even higher levels of control over the system. This could lead to unauthorized access to sensitive backup data or disruption of data recovery operations.

Technical details

An improper input validation vulnerability (CWE-20) exists in Dell PowerProtect Data Manager versions prior to 20.2.0.0. The flaw allows a remote attacker who already possesses high-level privileges to bypass intended access controls and achieve further elevation of privileges. The attack vector is network-based and does not require user interaction, though it does require valid high-privileged credentials. Dell has released version 20.2.0.0 to address this and other vulnerabilities.

Affected products

  • Dell PowerProtect Data Manager prior to 20.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats