Executive brief
Dell Cloud Disaster Recovery is a backup and recovery solution used to protect business data and applications. This vulnerability allows a low-privileged attacker with remote access to bypass security controls and access internal systems or data through forged server requests, potentially compromising the confidentiality of sensitive information.
Technical details
Dell Cloud Disaster Recovery versions 20.2 and prior contain a Server-Side Request Forgery (SSRF) vulnerability that allows an attacker to make arbitrary requests from the server to internal or external resources. The vulnerability requires low-level authentication and network access, with no user interaction needed. An unauthenticated attacker cannot exploit this directly—they must first obtain valid credentials. Exploitation enables limited information disclosure (CVSS C:L) but does not permit data modification or availability impact. The vulnerability is patched in version 20.3 and later.
Affected products
- Dell Cloud Disaster Recovery 20.2 and prior
Timeline
- 2026-08-26: disclosed
- 2026: patched: Fixed in version 20.3