Executive brief
Dell PowerProtect Data Domain is a storage solution used for backup, recovery, and archiving of enterprise data. A critical security flaw allows an unauthenticated attacker to bypass security checks and gain full control over the system remotely. This could lead to the total loss of data confidentiality and integrity, potentially allowing attackers to delete backups or steal sensitive corporate information.
Technical details
An improper authentication vulnerability exists in Dell PowerProtect Data Domain across multiple versions, including several Long Term Support (LTS) releases. The flaw allows a remote, unauthenticated attacker to bypass authentication mechanisms due to insufficient validation. Successful exploitation enables the attacker to gain unauthorized access and achieve full system compromise. Dell has released security updates to address this issue and recommends immediate upgrades to the latest available versions.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.7, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-07: disclosed: Initial advisory publication