Executive brief
Dell Cloud Disaster Recovery is a business-critical disaster recovery solution used to protect enterprise data and enable rapid system recovery. CVE-2026-70419 is a command injection vulnerability that allows a high-privileged attacker with remote access to execute arbitrary OS commands, potentially leading to complete compromise of the system, exposure of sensitive backup data, and disruption of disaster recovery capabilities.
Technical details
CVE-2026-70419 is an improper neutralization of special elements used in OS commands (CWE-78, OS command injection) in Dell Cloud Disaster Recovery versions 20.2 and prior. The vulnerability requires a high-privileged (authenticated admin-level) attacker with network access to exploit. The attack vector is network-based with low attack complexity and no user interaction required. Successful exploitation allows remote command execution with the privileges of the service, potentially enabling full system compromise, lateral movement, and data exfiltration. The fix is available in version 20.3 or later.
Affected products
- Dell Cloud Disaster Recovery 20.2 and prior
Timeline
- 2026-08-26: disclosed