Junglewise Threat Intelligence

CVE-2026-49813: Dell PowerProtect Data Domain OS command injection

CVE-2026-49813 · Severity: medium · CVSS 6.7 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security vulnerability has been identified that could allow a user with high-level administrative privileges to execute unauthorized commands on the underlying operating system. While this requires existing high-level access, it could allow an authorized administrator to bypass security restrictions and potentially compromise the integrity of the storage system.

Technical details

An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in OS commands. The vulnerability affects multiple versions including the 7.7.1.0-8.7 range and various LTS releases (2024, 2025, 2026). An attacker with high privileges and local access can exploit this flaw to execute arbitrary commands on the host operating system. Dell has released security updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: advisory: Initial publication of DSA-2026-278 and CVE-2026-49813

References

Related threats