CVE 8.8 HIGH

CVE-2026-26944_CVE-2026-26944

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action.

AI Analysis

Missing authentication for critical function vulnerability, allowing unauthenticated attackers to potentially execute arbitrary commands with root privileges.

Basic Information

ID CVE-2026-26944
Source dell
Published Apr 20, 2026 at 15:51

Affected Product

Vendor Dell
Product PowerProtect Data Domain
Affected Versions Dell PowerProtect Data Domain 0
Dell PowerProtect Data Domain 0
Dell PowerProtect Data Domain 0
Dell PowerProtect Data Domain 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Dell
Product PowerProtect Data Domain
Version 7.7.1.0-8.6, 8.3.1.0-8.3.1.20, 7.13.1.0-7.13.1.60

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.