CVE-2026-49813

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*
cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

History

08 Jul 2026, 19:32

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities - Vendor Advisory
First Time Dell
Dell data Domain Operating System
CPE cpe:2.3:o:dell:data_domain_operating_system:*:*:*:*:*:*:*:*

03 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-03 15:16

Updated : 2026-07-08 19:32


NVD link : CVE-2026-49813

Mitre link : CVE-2026-49813

CVE.ORG link : CVE-2026-49813


JSON object : View

Products Affected

dell

  • data_domain_operating_system
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')