Junglewise Threat Intelligence

CVE-2026-46730: Dell PowerProtect Data Domain incorrect authorization

CVE-2026-46730 · Severity: medium · CVSS 4.2 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for data backup, archiving, and disaster recovery. A security vulnerability has been identified where a user who already has high-level administrative access to the local system could execute unauthorized commands. While this requires existing high privileges, it could allow an administrator to bypass intended restrictions or perform actions outside of their authorized scope.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Dell PowerProtect Data Domain across multiple versions, including the LTS2024, LTS2025, and LTS2026 release branches. The flaw allows a high-privileged attacker with local access to the system to bypass authorization checks and execute commands that should otherwise be restricted. The vulnerability is exploited locally and requires the attacker to already possess high-level permissions (PR:H). Dell has released security updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: advisory
  • 2026-07-03: disclosed

References

Related threats