Junglewise Threat Intelligence

CVE-2026-53480: Dell PowerProtect Data Domain path traversal in restricted directory

CVE-2026-53480 · Severity: low · CVSS 2.7 · Published 2026-07-08

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A security flaw has been identified that could allow a user with high-level administrative privileges to modify files they should not have access to. While this requires existing high-level access, it could lead to unauthorized changes to system or data files, potentially impacting the integrity of the storage environment.

Technical details

A path traversal vulnerability (CWE-22) exists in Dell PowerProtect Data Domain due to improper limitation of pathnames to restricted directories. The flaw affects multiple versions across the 7.x and 8.x branches, including LTS releases. A remote attacker with high privileges (PR:H) can exploit this to access or modify files outside of the intended directory structure. While the impact is limited to unauthorized file modification (Integrity: Low) and does not grant confidentiality or availability impacts according to the CVSS score, it represents a breakdown in filesystem sandboxing. Dell has released security updates (8.8.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80) to remediate this issue.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 - 8.7, 8.6.1.0 - 8.6.1.10 (LTS2026), 8.3.1.0 - 8.3.1.30 (LTS2025), 7.13.1.0 - 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-08: disclosed: Initial publication of the advisory
  • 2026-07-08: advisory: Dell Security Advisory DSA-2026-278 released

References

Related threats