Executive brief
Dell PowerProtect Data Manager is a data backup and recovery solution used by enterprises to protect critical business data. A stack buffer overflow vulnerability in the file-level restore agent could allow a privileged attacker to crash the application or execute arbitrary code, potentially compromising the confidentiality and integrity of the system and the data it manages.
Technical details
CVE-2026-73600 is a stack buffer overflow vulnerability in the file-level restore agent component of Dell PowerProtect Data Manager versions 20.2.0.0 and below. The vulnerability requires local or adjacent network access and a user with low-level privileges to exploit. An attacker with these credentials can trigger the buffer overflow condition, potentially leading to information disclosure, denial of service, or code execution. The CVSS 3.1 vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates local attack surface with low complexity. Dell has released patched version 20.3.0.0 to address this and related vulnerabilities.
Affected products
- Dell PowerProtect Data Manager 20.2.0.0 and below
Timeline
- 2026-09-03: disclosed
- 2026-08-24: patched: Patch version 20.3.0.0 released