Junglewise Threat Intelligence

CVE-2026-44276: Dell PowerProtect Data Manager information exposure in REST API

CVE-2026-44276 · Severity: medium · CVSS 6 · Published 2026-07-22

Technologies: Dell Powerprotect Data Manager. Vendors: Dell.

Executive brief

Dell PowerProtect Data Manager, a solution for protecting and managing enterprise data, contains a security vulnerability in its management interface. A highly privileged user with local access to the system could exploit this flaw to view sensitive information they are not authorized to see. This could lead to the exposure of internal system details or configuration data, potentially aiding further unauthorized activities.

Technical details

Dell PowerProtect Data Manager is vulnerable to an information exposure (CWE-200) within its REST API component. The vulnerability allows a high-privileged attacker with local access to the system to retrieve sensitive information that should be restricted. The root cause is improper exposure of sensitive data to unauthorized actors via API responses. Exploitation requires local access and high-level administrative privileges, but the impact carries a scope change (S:C), indicating the leaked information may affect components beyond the immediate API environment. Dell has released version 20.2.0.0 to remediate this issue.

Affected products

  • Dell PowerProtect Data Manager prior to 20.2.0.0

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats