Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A critical security flaw allows an unauthorized person to access restricted system files over the network. If exploited, an attacker could take complete control of the system, potentially leading to the theft or destruction of sensitive backup data and a total loss of system availability.
Technical details
A path traversal vulnerability (CWE-22) exists in Dell PowerProtect Data Domain due to improper limitation of pathnames to restricted directories. An unauthenticated, remote attacker can exploit this flaw by sending specially crafted requests to the system to access files outside of the intended directory. Successful exploitation can lead to unauthorized system access and full administrative control. The vulnerability affects multiple versions including the 7.7.x through 8.7 branches and several Long Term Support (LTS) releases. Dell has released security updates (e.g., 8.8.0.0, 8.6.1.20, 8.3.1.40, 7.13.1.80) to address this issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-07: advisory: Dell published security advisory DSA-2026-278
- 2026-07-07: disclosed