CVE-2026-40712

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:*

History

29 Jul 2026, 17:40

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000488847/dsa-2026-287-security-update-dell-powerprotect-data-manager-for-multiple-security-vulnerabilities - Vendor Advisory
First Time Dell
Dell powerprotect Data Manager
CPE cpe:2.3:a:dell:powerprotect_data_manager:*:*:*:*:*:*:*:*

22 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-22 16:17

Updated : 2026-07-29 17:40


NVD link : CVE-2026-40712

Mitre link : CVE-2026-40712

CVE.ORG link : CVE-2026-40712


JSON object : View

Products Affected

dell

  • powerprotect_data_manager
CWE
CWE-20

Improper Input Validation