Executive brief
Dell PowerProtect One is a backup and disaster recovery management platform. A low-privileged authenticated attacker can exploit an OS command injection flaw to execute arbitrary commands on the system with full system privileges, potentially compromising all protected data and backup operations.
Technical details
CVE-2026-68861 is an OS command injection vulnerability (improper neutralization of special elements in OS commands) in Dell PowerProtect One versions 20.1.0.0 and below. The vulnerability requires a low-privilege authenticated user and network access to exploit, with no user interaction needed. A successful exploit allows remote code execution on the affected system. The CVSS v3.1 vector indicates high impact across confidentiality, integrity, and availability. Patches are available via Dell security update DSA-2026-369.
Affected products
- Dell powerprotect_one
Timeline
- 2026-08-26: disclosed
- 2026-08-26: advisory: Dell DSA-2026-369 published