Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security flaw has been identified that could allow a user with high-level administrative privileges to modify files they should not have access to. While this requires existing high-level access, it could lead to unauthorized changes to system or data files, potentially impacting the integrity of the storage environment.
Technical details
A path traversal vulnerability (CWE-22) exists in Dell PowerProtect Data Domain due to improper limitation of pathnames to restricted directories. The flaw affects multiple versions across the 7.x and 8.x branches, including LTS releases. A remote attacker with high privileges (PR:H) can exploit this to access or modify files outside of the intended directory structure. While the impact is limited to unauthorized file modification (Integrity: Low) and does not grant confidentiality or availability impacts according to the CVSS score, it represents a breakdown in filesystem sandboxing. Dell has released security updates (8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80) to remediate this issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 - 8.7, 8.6.1.0 - 8.6.1.10 (LTS2026), 8.3.1.0 - 8.3.1.30 (LTS2025), 7.13.1.0 - 7.13.1.70 (LTS2024)
Timeline
- 2026-07-08: disclosed: Initial publication of the advisory
- 2026-07-08: advisory: Dell Security Advisory DSA-2026-278 released