Junglewise Threat Intelligence

CVE-2026-79939: Dell PowerProtect Cyber Recovery symlink following vulnerability

CVE-2026-79939 · Severity: medium · CVSS 5.8 · Published 2026-08-26

Executive brief

Dell PowerProtect Cyber Recovery is a backup and disaster recovery system used to protect critical business data. A local privilege escalation vulnerability allows a low-privileged attacker with system access to inject malicious scripts, potentially compromising the integrity of backup data and recovery operations. This could enable attackers to corrupt backups, escalate privileges, or establish persistence on the system.

Technical details

This is a Unix symbolic link (symlink) following vulnerability in Dell PowerProtect Cyber Recovery versions prior to 20.3. A low-privileged local attacker with system access can exploit insecure symlink handling to achieve script injection. The vulnerability requires local access to the affected system and does not require elevated privileges to trigger. Successful exploitation allows an attacker to inject scripts into privileged processes, potentially leading to privilege escalation and full system compromise. Dell released patches in version 20.3 and later to address this issue.

Affected products

  • Dell PowerProtect Cyber Recovery Prior to 20.3

Timeline

  • 2026-08-26: disclosed
  • 2026: patched: Fixed in version 20.3 and later

References

Related threats