Junglewise Threat Intelligence

CVE-2026-46465: Dell PowerProtect Data Domain format string vulnerability

CVE-2026-46465 · Severity: medium · CVSS 5.5 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security vulnerability has been identified that could allow a high-privileged user to crash the system or access sensitive information. This could lead to temporary service outages or the exposure of internal system data, though it requires the attacker to already have significant administrative access.

Technical details

Dell PowerProtect Data Domain (multiple versions including LTS releases) is vulnerable to an externally-controlled format string (CWE-134). The flaw exists because the application fails to properly validate or sanitize input used in format string functions. A remote attacker with high privileges can exploit this by submitting specially crafted input, potentially leading to a process crash (Denial of Service) or the reading of sensitive memory contents (Information Disclosure). Remediation is available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 - 8.7, 8.6.1.0 - 8.6.1.10 (LTS2026), 8.3.1.0 - 8.3.1.30 (LTS2025), 7.13.1.0 - 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed
  • 2026-07-03: advisory

References