Junglewise Threat Intelligence

CVE-2026-44268: Dell PowerProtect Data Domain incorrect permission assignment

CVE-2026-44268 · Severity: medium · CVSS 4.4 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a backup and data protection storage solution. A security vulnerability exists where certain critical system resources have incorrect permission settings. If exploited by a user who already has high-level access to the system, it could allow them to access sensitive information they are not authorized to see, potentially compromising data privacy.

Technical details

Dell PowerProtect Data Domain contains an incorrect permission assignment vulnerability (CWE-732) affecting multiple versions including the 7.7.x, 8.x, and various LTS releases. The flaw stems from improper access controls on critical system resources. An attacker must already possess high privileges and local access to the system to exploit this vulnerability. Successful exploitation allows the attacker to gain unauthorized access to sensitive data or resources, though it does not inherently provide a path to system-wide administrative control or service disruption. Dell has released updates (e.g., 8.7.0.0, 8.6.1.20, 8.3.1.40, 7.13.1.80) to remediate the issue.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10, 8.3.1.0 through 8.3.1.30, 7.13.1.0 through 7.13.1.70

Timeline

  • 2026-07-03: advisory: Initial advisory published by Dell and NVD

References

Related threats