Executive brief
Dell PowerProtect Cyber Recovery is enterprise backup and disaster recovery software used to protect critical business data. An SQL injection vulnerability in versions 20.2 and earlier allows low-privileged attackers with network access to query and extract sensitive information from the underlying database, potentially exposing customer data and backup contents.
Technical details
The vulnerability is an improper neutralization of special elements in SQL commands (SQL injection, CWE-89) in Dell PowerProtect Cyber Recovery versions 20.2 and prior. The flaw allows a low-privileged attacker with remote network access to inject malicious SQL queries, bypassing input validation. An attacker can exploit this to read sensitive data from the database, including backup metadata and potentially customer information. The vulnerability does not appear to be actively exploited in the wild. Patches are available via Dell security update DSA-2026-370.
Affected products
- Dell PowerProtect Cyber Recovery 20.2 and prior
Timeline
- 2026-08-26: disclosed
- 2026-08: patched: Security update DSA-2026-370 released