Junglewise Threat Intelligence

CVE-2026-46463: Dell PowerProtect Data Domain integer overflow denial of service

CVE-2026-46463 · Severity: medium · CVSS 6.5 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A vulnerability in this system could allow a remote attacker to cause a denial-of-service condition, potentially disrupting data backup and recovery operations. This could lead to temporary unavailability of critical data protection services.

Technical details

Dell PowerProtect Data Domain is affected by an integer overflow or wraparound vulnerability (CWE-190). The flaw exists in multiple versions across several Long Term Support (LTS) release branches. An unauthenticated attacker with network access can exploit this vulnerability, though the attack complexity is rated as high. Successful exploitation primarily impacts availability by causing a denial-of-service (DoS) state, though a minor impact on integrity is also noted in the CVSS vector. Dell has released security updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 - 8.7, 8.6.1.0 - 8.6.1.10 (LTS2026), 8.3.1.0 - 8.3.1.30 (LTS2025), 7.13.1.0 - 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed: Initial advisory publication

References

Related threats