Executive brief
Dell PowerProtect Data Domain is a storage appliance used for backup, archiving, and disaster recovery. A vulnerability in this system could allow a user who already has high-level administrative privileges to execute unauthorized operating system commands. While this requires existing high-level access, it could allow an administrator to bypass intended software restrictions or further compromise the underlying system.
Technical details
An OS command injection vulnerability (CWE-78) exists in Dell PowerProtect Data Domain due to improper neutralization of special elements used in OS commands. The vulnerability affects multiple versions including the 7.7.1.0-8.6 range and various LTS releases (2024, 2025, 2026). An attacker with high privileges and local access can exploit this flaw to execute arbitrary commands on the underlying operating system. This could lead to a complete compromise of the confidentiality, integrity, and availability of the system. Dell has released updates (8.7.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80) to remediate this issue.
Affected products
- Dell PowerProtect Data Domain 7.7.1.0 through 8.6, 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), 7.13.1.0 through 7.13.1.70 (LTS2024)
Timeline
- 2026-07-03: advisory: Initial publication of the advisory