Executive brief
Dell PowerProtect One is a backup and data protection platform used to safeguard enterprise data. An authorization bypass vulnerability in versions 20.1.0.0 and below allows a low-privileged attacker with remote network access to tamper with protected information, potentially modifying critical backup data or metadata without proper authorization.
Technical details
This vulnerability is an authorization bypass through user-controlled key (CWE-639) in Dell PowerProtect One versions 20.1.0.0 and earlier. A low-privileged, authenticated remote attacker can exploit a flawed authorization mechanism that relies on user-supplied input to gain unauthorized access to sensitive functions. The attack requires network access and valid low-privilege credentials, but no user interaction. Successful exploitation allows an attacker to modify (tamper with) data and configurations. Dell has released security patches to address this issue.
Affected products
- Dell PowerProtect One 20.1.0.0 and below
Timeline
- 2026-08-26: disclosed