Junglewise Threat Intelligence

CVE-2026-44269: Dell PowerProtect Data Domain link following vulnerability

CVE-2026-44269 · Severity: medium · CVSS 4.4 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a backup and data protection storage solution. A security vulnerability has been identified where a user with high-level administrative privileges could gain unauthorized access to files they should not be able to reach by manipulating file links. While this requires existing high-level access to the system, it could allow an administrator to bypass certain internal security restrictions.

Technical details

An improper link resolution (CWE-59) vulnerability exists in Dell PowerProtect Data Domain across multiple versions, including LTS releases. The flaw occurs when the system follows symbolic or hard links without properly validating the target, allowing a local attacker with high privileges to access files outside of their intended scope. Exploitation requires local access and high-level permissions (PR:H). Successful exploitation results in a loss of confidentiality. Dell has released security updates (DSA-2026-278) to address this issue in versions 8.7.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References

Related threats