No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 21 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Authentication Allows Remote Root Command Execution on Dell PowerProtect Data Domain |
Mon, 20 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell powerprotect Data Domain |
|
| Vendors & Products |
Dell
Dell powerprotect Data Domain |
Mon, 20 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action. | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2026-04-20T18:02:52.279Z
Reserved: 2026-02-16T18:04:20.508Z
Link: CVE-2026-26944
Updated: 2026-04-20T18:02:42.569Z
Status : Awaiting Analysis
Published: 2026-04-20T16:16:42.223
Modified: 2026-04-20T19:05:30.750
Link: CVE-2026-26944
No data.
OpenCVE Enrichment
Updated: 2026-04-21T00:15:16Z