Junglewise Threat Intelligence

CVE-2026-67275: Dell PowerProtect One cache poisoning via insufficiently trustworthy component

CVE-2026-67275 · Severity: medium · CVSS 5.3 · Published 2026-08-26

Executive brief

Dell PowerProtect One is a data protection and disaster recovery platform used to safeguard critical business systems and data. An unauthenticated attacker can exploit a reliance on insufficiently trustworthy components to poison cached data, potentially causing incorrect or malicious information to be served to users. This could lead to service disruption, incorrect recovery operations, or reputational damage if users lose confidence in backup integrity.

Technical details

Dell PowerProtect One versions 20.1.0.0 and below contain a CWE-829 (Reliance on Insufficiently Trustworthy Component) vulnerability that allows cache poisoning. The vulnerability is remotely exploitable by an unauthenticated attacker and requires user interaction; no authentication is needed to initiate the attack. An attacker can inject malicious content into cache mechanisms, causing the system to serve corrupted or falsified data on subsequent requests. Dell has issued security updates as part of DSA-2026-369 to remediate this and related vulnerabilities.

Affected products

  • Dell PowerProtect One 20.1.0.0 and below

Timeline

  • 2026-08-26: disclosed

References

Related threats