Junglewise Threat Intelligence

CVE-2026-41124: Dell PowerProtect Data Domain path traversal

CVE-2026-41124 · Severity: low · CVSS 2.3 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of corporate data. A vulnerability in this system could allow a user who already has high-level administrative access to view files they should not be able to see. While the risk is low because it requires existing high-level access, it could lead to the exposure of sensitive system information.

Technical details

A path traversal vulnerability (CWE-22) exists in Dell PowerProtect Data Domain due to improper limitation of pathnames to restricted directories. The flaw affects multiple versions including the 7.7.1.0-8.6 range and various LTS releases. An attacker must already possess high privileges and local access to the system to exploit this vulnerability. Successful exploitation allows the attacker to bypass directory restrictions to read sensitive files, resulting in unauthorized information exposure. Dell has released security updates (e.g., versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80) to remediate this issue.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10, 8.3.1.0 through 8.3.1.30, 7.13.1.0 through 7.13.1.70

Timeline

  • 2026-07-03: advisory: Initial publication of CVE-2026-41124 by Dell

References

Related threats