Junglewise Threat Intelligence

CVE-2026-46467: Dell PowerProtect Data Domain sensitive information disclosure in log files

CVE-2026-46467 · Severity: medium · CVSS 5.8 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain, a storage solution used for backup and data protection, is affected by a vulnerability where sensitive information is improperly recorded in system log files. A user with low-level access to the local system could read these logs to discover confidential data. This exposure could potentially assist an attacker in further compromising the system or accessing protected information.

Technical details

This vulnerability (CWE-532) involves the insertion of sensitive information into log files within Dell PowerProtect Data Domain. The flaw affects multiple versions including the 7.7.x-8.7 range and various LTS releases. An attacker with low-privileged local access can exploit this by reviewing system logs to extract sensitive data. The attack complexity is rated as high, suggesting specific conditions or timing may be required to capture the sensitive data. Dell has released security updates (DSA-2026-278) to address this and other vulnerabilities, with fixed versions including 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: advisory
  • 2026-07-03: disclosed

References

Related threats