Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of corporate data. A security vulnerability has been identified that could allow a high-privileged user to execute unauthorized commands on the system. If exploited, this could lead to a complete compromise of the storage appliance and the data it protects.
Technical details
Dell PowerProtect Data Domain contains an OS command injection vulnerability (CWE-78) due to improper neutralization of special elements in system commands. The vulnerability affects multiple versions across several release branches, including LTS2024, LTS2025, and LTS2026. An attacker with high privileges and network access can exploit this flaw to achieve arbitrary command execution on the underlying operating system. Dell has released updates to address this issue, with fixes available in versions 8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: disclosed: Initial publication of the CVE and Dell advisory.