Junglewise Threat Intelligence

CVE-2026-56086: Dell PowerProtect Data Domain incorrect authorization

CVE-2026-56086 · Severity: high · CVSS 8.8 · Published 2026-07-08

Technologies: Dell PowerProtect Data Domain. Vendors: Dell.

Executive brief

Dell PowerProtect Data Domain is a backup and storage solution used to protect and manage corporate data. A security flaw in the system's authorization checks could allow a user with low-level access to gain unauthorized permissions. This could lead to the exposure of sensitive data or unauthorized changes to the storage environment.

Technical details

Dell PowerProtect Data Domain is affected by an incorrect authorization vulnerability (CWE-863). The flaw exists in multiple versions, including the 7.7.1.0 through 8.6 branches and various Long Term Support (LTS) releases. A remote attacker with low-level authenticated privileges can exploit this vulnerability to bypass intended access controls. Successful exploitation results in unauthorized access to system resources, potentially compromising the confidentiality, integrity, and availability of the data protection platform. Dell has released security updates (DSA-2026-278) to address this issue, with fixed versions including 8.7.0.0, 8.6.1.20, 8.3.1.40, and 7.13.1.80 or later.

Affected products

  • Dell PowerProtect Data Domain 7.7.1.0 - 8.6, 8.6.1.0 - 8.6.1.10 (LTS2026), 8.3.1.0 - 8.3.1.30 (LTS2025), 7.13.1.0 - 7.13.1.70 (LTS2024)

Timeline

  • 2026-07-08: advisory: Initial publication of DSA-2026-278 and NVD entry.

References

Related threats