Executive brief
Dell PowerProtect Cyber Recovery is a backup and disaster recovery solution used by enterprises to protect critical data and systems. Versions prior to 20.3 contain an authentication flaw that allows a low-privileged attacker with network access to gain unauthorized access to the system, potentially exposing backup data and recovery capabilities to compromise.
Technical details
This vulnerability is classified as improper authentication affecting Dell PowerProtect Cyber Recovery versions prior to 20.3. A low-privileged attacker with remote network access can exploit the authentication bypass to gain unauthorized access to the system. The vulnerability allows an attacker to circumvent authentication controls, potentially leading to unauthorized system access, data exposure, and manipulation of recovery operations. Dell has released a security update (DSA-2026-370) addressing this and multiple third-party component vulnerabilities; systems should be updated to version 20.3 or later.
Affected products
- Dell PowerProtect Cyber Recovery prior to 20.3
Timeline
- 2026-08-26: disclosed
- 2026-08-26: advisory