Junglewise Threat Intelligence

CVE-2026-74770: Dell PowerProtect One OS command injection

CVE-2026-74770 · Severity: high · CVSS 8.8 · Published 2026-08-26

Executive brief

Dell PowerProtect One is a backup and recovery solution used to protect corporate data and applications. This vulnerability allows a low-privileged attacker with network access to execute arbitrary commands on the system, potentially compromising the entire backup infrastructure and the data it protects. An attacker could use this to steal, modify, or delete critical business data or disrupt backup operations.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in Dell PowerProtect One versions 20.1.0.0 and below that fails to properly sanitize user-controlled input passed to OS commands. A low-privileged authenticated attacker with network access can exploit this to execute arbitrary code with the privileges of the PowerProtect One service. The vulnerability requires valid credentials but does not require user interaction. Successful exploitation leads to remote code execution, giving an attacker complete control over the backup infrastructure.

Affected products

  • Dell PowerProtect One 20.1.0.0 and below

Timeline

  • 2026-08-26: disclosed

References

Related threats