Executive brief
Dell PowerProtect Data Manager, a platform for data protection and backup management, contains a security vulnerability in its management interface. A high-privileged user could exploit this flaw to execute unauthorized commands on the system remotely. This could lead to a significant compromise of the backup infrastructure, potentially impacting data integrity and system availability.
Technical details
An improper input validation vulnerability (CWE-20) exists in the REST API of Dell PowerProtect Data Manager. The flaw allows a high-privileged attacker with network access to the API to submit specially crafted requests that result in remote code execution. While the attack vector is over the network and requires no user interaction, it is mitigated by the requirement for high-level administrative privileges. Dell has addressed this vulnerability in version 20.2.0.0 and later.
Affected products
- Dell PowerProtect Data Manager prior to 20.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory