Junglewise Threat Intelligence

CVE-2026-68860: Dell PowerProtect Data Manager information disclosure via memory layout reliance

CVE-2026-68860 · Severity: medium · CVSS 6.8 · Published 2026-09-03

Technologies: Dell Powerprotect Data Manager. Vendors: Dell.

Executive brief

Dell PowerProtect Data Manager is a backup and disaster recovery appliance used by enterprises to protect critical data. This vulnerability allows an unauthenticated attacker to exploit how the system handles data in memory, potentially exposing sensitive information that could be used to launch phishing attacks against users. An attacker needs user interaction to trigger the exploit, but requires no authentication to attempt the attack.

Technical details

The vulnerability is a reliance on data/memory layout issue in PowerProtect Data Manager versions 20.2.0.0 and below. An unauthenticated remote attacker can exploit this via a network attack vector that requires user interaction and high complexity conditions. The vulnerability allows information disclosure and integrity compromise, enabling attackers to extract sensitive data for use in phishing campaigns. Dell has issued patches in version 20.3.0.0, and users should update immediately.

Affected products

  • Dell PowerProtect Data Manager 20.2.0.0 and below

Timeline

  • 2026-09-03: disclosed
  • 2026-08-24: advisory: Dell Security Advisory DSA-2026-368 initial release
  • 2026-08-26: patched: Patch available in version 20.3.0.0

References

Related threats