Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, archiving, and disaster recovery. A vulnerability in this system allows an attacker with high-level administrative privileges to bypass security protections and run unauthorized commands. If exploited, this could allow the attacker to gain full control over the storage appliance, potentially leading to the theft, modification, or deletion of sensitive backup data.
Technical details
An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in OS commands. The flaw is reachable over the network but requires high-privileged authentication (PR:H). Successful exploitation allows an attacker to bypass protection mechanisms and execute arbitrary commands with root-level permissions on the underlying operating system. Affected versions include the 7.7.1.0 through 8.7 branches and various LTS releases (2024, 2025, 2026). Dell recommends upgrading to versions 8.8.0.0, 8.6.1.20, 8.3.1.40, or 7.13.1.80 and later to remediate the issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-07: advisory: Initial publication of DSA-2026-278 and CVE-2026-53479