Executive brief
Dell PowerProtect Data Manager is a backup and data protection system used by enterprises to safeguard critical business data. A flaw in the REST API allows low-privileged users to bypass authorization controls and modify data or configuration settings they should not have access to. An attacker with basic user credentials could escalate their privileges and compromise backup integrity or cause data loss.
Technical details
CVE-2026-74769 is an incorrect authorization vulnerability in the REST API of Dell PowerProtect Data Manager version 20.2.0.0 and below. A low-privileged authenticated remote attacker can bypass authorization checks on API endpoints, achieving privilege escalation or unauthorized modification of protected resources. The attack requires network access to the API and valid login credentials, but no administrator privileges. This results in a protection mechanism bypass, allowing attackers to manipulate backup policies or access policies. Dell released version 20.3.0.0 as the patched version.
Affected products
- Dell PowerProtect Data Manager 20.2.0.0 and below
Timeline
- 2026-09-03: disclosed: NVD publication
- 2026-08-24: advisory: Dell DSA-2026-368 initial release
- 2026-08-26: patched: Patch available in version 20.3.0.0