Junglewise Threat Intelligence

CVE-2026-46466: Dell PowerProtect Data Domain use of less trusted source

CVE-2026-46466 · Severity: low · CVSS 2.7 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain, a storage solution used for backup and data protection, is affected by a security vulnerability. A remote attacker with high-level administrative privileges could exploit this flaw to modify or tamper with information on the system. While the impact is limited to data integrity and requires significant existing access, it could allow an authorized user to perform unauthorized changes.

Technical details

Dell PowerProtect Data Domain contains a 'Use of Less Trusted Source' vulnerability (CWE-348). The flaw exists in versions 7.7.1.0 through 8.7, including various LTS releases. A remote attacker who already possesses high privileges can exploit this vulnerability to tamper with information within the system. The attack vector is network-based and requires no user interaction, though the prerequisite for high privileges results in a low CVSS score of 2.7. Dell has released security updates (8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80) to remediate this issue.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: advisory
  • 2026-07-03: disclosed

References

Related threats