Junglewise Threat Intelligence

CVE-2026-71171: Dell Cloud Disaster Recovery OS command injection in REST API

CVE-2026-71171 · Severity: high · CVSS 7.2 · Published 2026-08-26

Executive brief

Dell Cloud Disaster Recovery is a backup and recovery solution used to protect business data and systems. An authenticated attacker with high privilege access could inject malicious operating system commands through the REST API, allowing them to execute arbitrary code on the affected server and potentially compromise all data managed by the recovery system.

Technical details

The vulnerability is an OS Command Injection flaw in the REST API of Dell Cloud Disaster Recovery versions 20.2 and prior, caused by improper neutralization of special elements in user-supplied input. A high-privileged attacker with network access can exploit this to execute arbitrary OS commands on the affected system. The attack requires high privilege credentials but no user interaction; successful exploitation grants full remote code execution capabilities. The issue is addressed in version 20.3 and later.

Affected products

  • Dell Cloud Disaster Recovery 20.2 and prior

Timeline

  • 2026-08-26: disclosed
  • 2026: patched: Version 20.3 contains remediation

References

Related threats