Executive brief
Dell PowerProtect Data Domain is a backup and data protection storage solution. A vulnerability in this system allows an attacker with high-level administrative privileges to execute unauthorized operating system commands remotely. This could lead to a complete compromise of the storage appliance, potentially impacting the integrity and availability of backed-up data.
Technical details
An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in OS commands. The vulnerability affects multiple versions across the 7.x and 8.x branches, including several Long Term Support (LTS) releases. An attacker must possess high privileges (PR:H) to exploit this flaw over the network. Successful exploitation allows for arbitrary command execution, which can lead to a full system compromise or bypass of security protection mechanisms. Dell has released security updates (DSA-2026-278) to address this issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: advisory: Initial publication of DSA-2026-278 and NVD entry