Executive brief
Dell PowerProtect Data Domain, a backup and recovery storage solution, is affected by a security vulnerability that could allow an authorized user to access sensitive information they should not be able to see. To exploit this, an attacker must already have high-level administrative privileges and local access to the system. While the risk is limited by the requirement for existing high-level access, it could lead to the exposure of protected data.
Technical details
A link following vulnerability (CWE-59) exists in Dell PowerProtect Data Domain due to improper link resolution before file access. An attacker with high privileges and local access to the system can exploit this flaw to bypass intended file access restrictions, potentially leading to unauthorized information exposure. The vulnerability affects multiple versions including the 7.7.x through 8.7 branches and various Long Term Support (LTS) releases. Dell has released updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: advisory
- 2026-07-03: disclosed