Executive brief
Dell PowerProtect Data Manager is a platform used by organizations to manage data protection and backup operations. A security vulnerability in its management interface could allow a user with high-level permissions to gain even greater control over the system. If exploited, this could lead to unauthorized access to sensitive backup data or the ability to disrupt critical data recovery operations.
Technical details
An improper input validation vulnerability exists in the REST API of Dell PowerProtect Data Manager. The flaw is located within the input handling mechanisms of the API, where insufficient validation allows a high-privileged remote attacker to escalate their existing permissions. According to the CVSS vector, this vulnerability has a 'Changed' scope (S:C), meaning an exploit can impact components beyond the immediate security scope of the REST API. Attackers can achieve full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to upgrade to version 20.2.0.0 or later to remediate this issue.
Affected products
- Dell PowerProtect Data Manager prior to 20.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory