Executive brief
Dell PowerProtect Data Manager is a platform used by organizations to manage data backup and recovery operations. A security flaw in its identity management component allows a user with low-level access to gain higher-level administrative privileges. This could allow an unauthorized individual to take full control of the backup system, potentially leading to the deletion of backups or unauthorized access to sensitive corporate data.
Technical details
Dell PowerProtect Data Manager is vulnerable to an 'Incorrect Generation of Security Tokens' (CWE-1270) within its Identity and Access Management (IAM) component. The flaw allows a remote attacker who already possesses low-privileged credentials to generate or manipulate security tokens to gain elevated permissions. This is a network-based attack that does not require user interaction. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (CVSS 8.8). The issue is resolved in version 20.2.0.0 and later.
Affected products
- Dell PowerProtect Data Manager prior to 20.2.0.0
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory