CVE-2026-26944
published 2026-04-20CVE-2026-26944: Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through…
PriorityP261high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.54%
41.3th percentile
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | data_domain_operating_system | >= 7.14.0.0 < 8.3.1.30 | 8.3.1.30 |
| dell | data_domain_operating_system | >= 7.7.1.0 < 7.13.1.70 | 7.13.1.70 |
| dell | data_domain_operating_system | >= 8.4.0.0 < 8.6.1.0 | 8.6.1.0 |
| dell | powerprotect_data_domain | < 8.6.1.10, 8.7.0.0 or later | 8.6.1.10, 8.7.0.0 or later |
| dell | powerprotect_data_domain | < 8.3.1.30 or later | 8.3.1.30 or later |
| dell | powerprotect_data_domain | < 7.13.1.70 or later | 7.13.1.70 or later |
| dell | powerprotect_data_domain | < 2.7.9 with DD OS 8.3.1.30 | 2.7.9 with DD OS 8.3.1.30 |
| dell | powerprotect_dp_series_appliance | < 2.7.9 | 2.7.9 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmwv-mfjf-w46v: Dell PowerProtect Data Domain, versions 7
ghsa_unreviewed·2026-04-20
CVE-2026-26944 [HIGH] CWE-306 GHSA-hmwv-mfjf-w46v: Dell PowerProtect Data Domain, versions 7
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action.
VulDB
Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 missing authentication (dsa-2026-060 / EUVD-2026-23899)
vuldb·2026-04-20·CVSS 8.8
CVE-2026-26944 [HIGH] Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 missing authentication (dsa-2026-060 / EUVD-2026-23899)
A vulnerability was found in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6. It has been classified as critical. The impacted element is an unknown function. This manipulation causes missing authentication.
This vulnerability is handled as CVE-2026-26944. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-20
Published