Junglewise Threat Intelligence

CVE-2026-53479: Dell PowerProtect Data Domain OS command injection

CVE-2026-53479 · Severity: high · CVSS 7.2 · Published 2026-07-07

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, archiving, and disaster recovery. A vulnerability in this system allows an attacker with high-level administrative privileges to bypass security protections and run unauthorized commands. If exploited, this could allow the attacker to gain full control over the storage appliance, potentially leading to the theft, modification, or deletion of sensitive backup data.

Technical details

An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in OS commands. The flaw is reachable over the network but requires high-privileged authentication (PR:H). Successful exploitation allows an attacker to bypass protection mechanisms and execute arbitrary commands with root-level permissions on the underlying operating system. Affected versions include the 7.7.1.0 through 8.7 branches and various LTS releases (2024, 2025, 2026). Dell recommends upgrading to versions 8.8.0.0, 8.6.1.20, 8.3.1.40, or 7.13.1.80 and later to remediate the issue.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-07: advisory: Initial publication of DSA-2026-278 and CVE-2026-53479

References

Related threats