Junglewise Threat Intelligence

CVE-2026-49814: Dell PowerProtect Data Domain OS command injection

CVE-2026-49814 · Severity: high · CVSS 7.2 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of corporate data. A security vulnerability has been identified that could allow a high-privileged user to execute unauthorized commands on the system. If exploited, this could lead to a complete compromise of the storage appliance and the data it protects.

Technical details

Dell PowerProtect Data Domain contains an OS command injection vulnerability (CWE-78) due to improper neutralization of special elements in system commands. The vulnerability affects multiple versions across several release branches, including LTS2024, LTS2025, and LTS2026. An attacker with high privileges and network access can exploit this flaw to achieve arbitrary command execution on the underlying operating system. Dell has released updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed: Initial publication of the CVE and Dell advisory.

References

Related threats