Executive brief
Dell PowerProtect Data Domain, a specialized storage solution for data backup and protection, is affected by a security flaw in its access control system. A user with low-level permissions could exploit this weakness to modify or tamper with information they should not be able to access. This could potentially compromise the integrity of backup data or system configurations.
Technical details
An improper access control vulnerability (CWE-284) exists in the Role-Based Access Control (RBAC) component of Dell PowerProtect Data Domain. The flaw allows a remote attacker with low-level authenticated privileges to bypass intended restrictions and perform unauthorized information tampering. The vulnerability affects multiple release branches including LTS2024, LTS2025, and LTS2026. Dell has released security updates to address this issue, with fixes available in versions 8.7.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: advisory
- 2026-07-03: disclosed