Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security vulnerability in its web interface could allow an attacker to inject malicious scripts that execute when a legitimate user visits the management console. If successful, this could lead to the theft of login sessions, unauthorized access to sensitive information, or the performance of unintended actions on behalf of the user.
Technical details
Dell PowerProtect Data Domain is vulnerable to stored cross-site scripting (XSS) due to improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by injecting malicious scripts into the application that are later executed in the context of a victim's browser session. Successful exploitation requires a user to interact with the affected component and can result in session hijacking, client-side request forgery (CSRF), or sensitive information disclosure. Dell has released security updates to address this issue in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory