Junglewise Threat Intelligence

CVE-2026-68863: Dell PowerProtect One stack-based buffer overflow

CVE-2026-68863 · Severity: high · CVSS 7.5 · Published 2026-08-26

Executive brief

Dell PowerProtect One is a data protection and disaster recovery platform used by enterprises to safeguard critical systems and backups. An unauthenticated attacker with network access could trigger a stack-based buffer overflow, causing the PowerProtect One service to crash and denying legitimate users access to backup and recovery capabilities. This vulnerability requires no authentication or user interaction to exploit.

Technical details

The vulnerability is a stack-based buffer overflow in Dell PowerProtect One versions 20.1.0.0 and below. An unauthenticated attacker with network reachability can send a specially crafted request to trigger the buffer overflow, resulting in a denial of service condition. The attack vector is network-based with low complexity and no authentication required. While the CVSS score (7.5) indicates high severity, the impact is limited to availability; no confidentiality or integrity compromise is possible through this specific flaw. A patch is available from Dell to remediate this and related vulnerabilities.

Affected products

  • Dell PowerProtect One 20.1.0.0 and below

Timeline

  • 2026-08-26: disclosed

References

Related threats