CVE-2026-35154
published 2026-04-20CVE-2026-35154: Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions…
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.09%
0.5th percentile
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability.
A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | data_domain_operating_system | >= 7.13.1.0 < 7.13.1.70 | 7.13.1.70 |
| dell | data_domain_operating_system | >= 8.3.0.0 < 8.3.1.30 | 8.3.1.30 |
| dell | data_domain_operating_system | >= 8.4.0.0 < 8.6.1.0 | 8.6.1.0 |
| dell | powerprotect_data_domain_appliances | < 8.7.0.1 or later | 8.7.0.1 or later |
| dell | powerprotect_data_domain_appliances | < 8.3.1.30 or later | 8.3.1.30 or later |
| dell | powerprotect_data_domain_appliances | < 7.13.1.70 or later | 7.13.1.70 or later |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 privileges management (dsa-2026-060 / EUVD-2026-23917)
vuldb·2026-04-20·CVSS 6.3
CVE-2026-35154 [MEDIUM] Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 privileges management (dsa-2026-060 / EUVD-2026-23917)
A vulnerability labeled as critical has been found in Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0. This issue affects some unknown processing. Such manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2026-35154. The attack can only be performed from a local environment. No exploit is available.
GHSA
GHSA-p3pj-xf59-54r5: Dell PowerProtect Data Domain appliances, versions 7
ghsa_unreviewed·2026-04-20
CVE-2026-35154 [MEDIUM] CWE-269 GHSA-p3pj-xf59-54r5: Dell PowerProtect Data Domain appliances, versions 7
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-20
Published