Junglewise Threat Intelligence

CVE-2026-53478: Dell PowerProtect Data Domain OS command injection

CVE-2026-53478 · Severity: high · CVSS 7.2 · Published 2026-07-03

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a backup and data protection storage solution used to secure and manage enterprise data. A vulnerability in this system could allow a high-privileged user to execute unauthorized commands on the underlying operating system. This could lead to a complete compromise of the storage appliance, potentially impacting the integrity and availability of backed-up data.

Technical details

Dell PowerProtect Data Domain contains an OS command injection vulnerability due to improper neutralization of special elements used in operating system commands. The vulnerability affects multiple versions including the 7.7.1.0 through 8.7 branch and various Long Term Support (LTS) releases. An attacker with high privileges and remote network access can exploit this flaw to execute arbitrary commands on the host OS. While the attack requires existing high-level credentials, successful exploitation results in full system compromise. Dell has released security updates to address this issue and recommends upgrading to the latest available versions.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-03: disclosed: Initial publication of the advisory

References

Related threats