Junglewise Threat Intelligence

CVE-2026-74768: Dell PowerProtect Data Manager SSRF in REST API

CVE-2026-74768 · Severity: medium · CVSS 4.1 · Published 2026-09-03

Technologies: Dell Powerprotect Data Manager. Vendors: Dell.

Executive brief

Dell PowerProtect Data Manager is a backup and recovery solution used by enterprises to protect critical data. A Server-Side Request Forgery (SSRF) vulnerability in its REST API could allow a high-privileged attacker to make unauthorized network requests from the server, potentially exposing sensitive information or accessing internal systems. This affects versions 20.2.0.0 and below, with patches available in version 20.3.0.0.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability in the Dell PowerProtect Data Manager REST API. The vulnerability requires high-level administrative privileges and network access to the API endpoint. An authenticated attacker can exploit this to make unauthorized HTTP requests from the server to internal or external systems, potentially bypassing network segmentation or accessing sensitive data. The attack vector is network-based with high privilege requirements. Dell has patched the vulnerability in version 20.3.0.0.

Affected products

  • Dell PowerProtect Data Manager 20.2.0.0 and below

Timeline

  • 2026-09-03: disclosed
  • 2026-08-24: patched: Version 20.3.0.0 available

References

Related threats