Executive brief
Dell PowerProtect Data Domain is a backup and data protection storage solution. A security vulnerability has been identified where a user with high-level administrative privileges could gain unauthorized access to files they should not be able to reach by manipulating file links. While this requires existing high-level access to the system, it could allow an administrator to bypass certain internal security restrictions.
Technical details
An improper link resolution (CWE-59) vulnerability exists in Dell PowerProtect Data Domain across multiple versions, including LTS releases. The flaw occurs when the system follows symbolic or hard links without properly validating the target, allowing a local attacker with high privileges to access files outside of their intended scope. Exploitation requires local access and high-level permissions (PR:H). Successful exploitation results in a loss of confidentiality. Dell has released security updates (DSA-2026-278) to address this issue in versions 8.7.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: disclosed
- 2026-07-03: advisory