By vendor

Dell vulnerabilities

Known CVEs affecting Dell products, prioritized by severity, with SEC.co remediation and detection guidance.

55 published vulnerabilities

  • CVE-2026-35065HIGH 8.8

    Dell PowerFlex Manager versions before 5.1.0.1 contain a vulnerability that allows an unauthenticated attacker on the adjacent network to access critical functions without authentication. This could lead to unauthorized code execution, data theft, data modification, service disruption, and remote command execution. The vulnerability is rated HIGH severity and requires immediate attention for affected deployments.

  • CVE-2026-44272HIGH 8.8

    Dell Wyse Management Suite versions before 2605 contain a SQL injection flaw that allows attackers with low-level network access to bypass authentication controls and gain unauthorized access to the system. An authenticated user on the network can craft malicious input to manipulate database queries, potentially extracting sensitive data or modifying system configurations.

  • CVE-2026-54469HIGH 8.8

    Dell Unisphere for PowerMax versions 10.3.0.5 and earlier contain a flaw that allows a low-privileged attacker with remote access to execute arbitrary commands as root. The vulnerability stems from unsafe handling of serialized data, meaning an attacker can craft malicious input that, when deserialized by the application, triggers code execution at the highest privilege level. This is a critical escalation path: an attacker who gains even basic user access can weaponize this flaw to take complete control of the storage management infrastructure.

  • CVE-2026-56086HIGH 8.8

    Dell PowerProtect Data Domain contains a flaw in how it checks user permissions. A remote attacker with low-level credentials can bypass authorization controls and gain unauthorized access to the system. This affects multiple versions across different release lines (7.7 through 8.6 and several LTS branches). The vulnerability allows a low-privileged user to escalate their access in ways the system should prevent.

  • CVE-2026-56690HIGH 8.5

    Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection flaw that allows attackers with low-level user credentials and network access to query the database directly. An attacker could extract sensitive data, modify information, or gain unauthorized access to storage infrastructure management functions without requiring special privileges or user interaction.

  • CVE-2026-32804HIGH 8.1

    Dell PowerFlex Manager versions before 5.1.0.1 contain an authentication flaw that allows an attacker on the same network segment to gain unauthorized access without credentials. The vulnerability does not require any user interaction and can be exploited by someone already positioned on an adjacent network—making it particularly risky in environments where trust in lateral network access may be assumed. An attacker exploiting this could modify storage configurations, disable services, or access sensitive data.

  • CVE-2026-44271HIGH 8.1

    Dell Wyse Management Suite (WMS) versions before 2605 contain a SQL injection flaw that allows a logged-in attacker to query or modify the underlying database without proper authorization. An attacker with low-level access to the management interface can craft malicious input to bypass SQL protections, potentially reading sensitive configuration data or disrupting system availability. The vulnerability requires network access and valid credentials but does not require user interaction to trigger.

  • CVE-2026-32652HIGH 7.8

    Dell AIOps Collector versions before 1.18.3 ship with hardcoded or default credentials that a local attacker can exploit to gain broad filesystem access. The vulnerability only affects new installations; systems that have been patched or upgraded to 1.18.3 or later are protected, regardless of their original version. This is a local-only attack requiring console access—remote exploitation is not possible.

  • CVE-2026-40715HIGH 7.8

    Dell ThinOS 10 versions before 2602_10.0765 contain an access control flaw that allows a user with basic system access to gain elevated administrative privileges. An attacker already on the system as a regular user could leverage this vulnerability to take full control, making it a critical privilege escalation risk for any organization relying on ThinOS-based thin clients or endpoints.

  • CVE-2026-44274HIGH 7.8

    Dell Wyse Management Suite (WMS) contains a flaw that allows an attacker with basic user privileges and local system access to bypass file access controls through improper link resolution. This could enable unauthorized access to sensitive system files or data that the attacker should not normally be able to read or modify. The vulnerability affects all versions before WMS 2605 and requires the attacker to already have a user account on the affected system.

  • CVE-2026-46461HIGH 7.8

    Dell Server Hardware Manager versions before 3.2.2 contain an access control flaw that allows a low-privileged user with local system access to escalate their privileges to a higher level. An attacker with a basic user account on the affected server could gain elevated permissions, potentially compromising the confidentiality, integrity, and availability of server operations and data.

  • CVE-2026-46733HIGH 7.8

    Dell Display and Peripheral Manager (DDPM) for Windows versions before 2.3 has an access control flaw that allows a user with basic local system access to run arbitrary code. An attacker would need to already have a foothold on the machine—either through a standard user account or through physical access—but once present, they could escalate their privileges and take full control of the system. This is a post-compromise risk rather than a worm-like threat.

  • CVE-2026-56689HIGH 7.7

    Dell PowerFlex Manager versions before 5.1.0.1 contain an SQL injection vulnerability that allows a low-privileged attacker with network access to run unauthorized database queries. The flaw could lead to exposure of sensitive data stored within PowerFlex Manager. This is a remote vulnerability that does not require special access conditions to trigger, making it a meaningful risk for organizations managing Dell storage infrastructure.

  • CVE-2026-22283HIGH 7.5

    Dell PowerFlex Manager versions before 5.1.0.1 contain a vulnerability that allows an unauthenticated, remote attacker to disclose sensitive information. The flaw stems from the inclusion of functionality from an untrusted control sphere—essentially, the product incorporates code or resources from an unvetted source that an attacker can manipulate to bypass security controls and access confidential data. While exploitation requires user interaction (a user must be present or perform an action), no authentication is needed, making this a meaningful risk for organizations running affected PowerFlex Manager instances.

  • CVE-2026-53482HIGH 7.5

    Dell PowerProtect Data Domain versions from 7.7.1.0 through 8.7, including multiple long-term support (LTS) releases, contain an integer overflow vulnerability that allows unauthenticated remote attackers to crash the system, disrupting backup and recovery operations. The vulnerability requires no authentication and no user interaction—an attacker simply needs network access to trigger a denial-of-service condition.

  • CVE-2026-49502HIGH 7.4

    Dell PowerFlex Manager versions before 5.1.0.1 contain a flaw that allows an attacker on the same network segment to bypass authentication controls and gain unauthorized access to the system. Without needing valid credentials, an adjacent network attacker could read sensitive data, modify information, or take unauthorized actions within PowerFlex Manager. This is particularly concerning for organizations that assume internal network access is inherently trusted.

  • CVE-2026-41121HIGH 7.3

    Dell Device Management Agent versions before 26.05 contain a link-following vulnerability that allows a low-privileged local attacker to escalate their privileges on an affected system. An attacker with basic user access could exploit a flaw in how the agent resolves file links to gain elevated permissions, potentially taking full control of the system.

  • CVE-2026-46734HIGH 7.3

    Dell Display and Peripheral Manager (DDPM) for Mac versions before 2.3 fail to properly validate SSL/TLS certificates, allowing an attacker with local access and low-level user privileges to intercept or spoof secure connections. By presenting a forged or expired certificate, an attacker could bypass the software's security protections and potentially steal sensitive data or modify device settings without detection.

  • CVE-2026-49506HIGH 7.2

    Dell Wyse Management Suite versions before 5.5 HF1 contain a path traversal vulnerability that allows a highly privileged remote attacker to bypass directory restrictions and execute arbitrary code on the system. Path traversal flaws occur when an application fails to properly sanitize file path inputs, allowing attackers to access files and directories outside the intended scope. In this case, the vulnerability is particularly dangerous because it leads directly to remote code execution in the hands of someone with elevated privileges.

  • CVE-2026-49814HIGH 7.2

    Dell PowerProtect Data Domain, a widely deployed deduplication and backup platform, contains a command injection flaw that allows authenticated attackers with high privileges to execute arbitrary system commands. Versions 7.7.1.0 through 8.7, along with multiple Long-Term Support (LTS) release branches, are affected. An attacker who gains high-level credentials or access can bypass application controls and run OS commands directly on the appliance, potentially compromising the entire backup infrastructure and any data stored within it.

  • CVE-2026-49815HIGH 7.2

    Dell PowerProtect Data Domain, a widely-deployed deduplication and backup storage system, contains an OS command injection vulnerability that allows high-privileged remote attackers to execute arbitrary commands on affected systems. The flaw affects multiple release branches spanning versions 7.7.1.0 through 8.7, with specific LTS versions also impacted. Exploitation requires elevated privileges and network access, but once triggered, grants an attacker direct command execution with system-level capabilities.

  • CVE-2026-53478HIGH 7.2

    A command injection vulnerability in Dell PowerProtect Data Domain allows authenticated users with administrative privileges to execute arbitrary operating system commands remotely. The vulnerability affects multiple release branches spanning versions 7.7.1.0 through 8.7, potentially giving an attacker the ability to compromise the integrity and confidentiality of backup data stored on affected systems.

  • CVE-2026-53479HIGH 7.2

    Dell PowerProtect Data Domain backup appliances in multiple versions contain an OS command injection flaw that allows authenticated high-privileged users to execute arbitrary commands with root-level access. An attacker with administrative credentials could bypass security controls and gain unrestricted control of the appliance. This is a serious vulnerability because it affects backup infrastructure—a critical component that adversaries often target to prevent recovery after ransomware attacks.

  • CVE-2026-35066HIGH 7.1

    Dell PowerFlex Manager versions before 5.1.0.1 contain an access control flaw that allows low-privileged remote attackers to cause denial of service. The vulnerability stems from improper enforcement of access restrictions, enabling an authenticated attacker to disrupt availability of the management platform without requiring elevated permissions or user interaction.

  • CVE-2026-41122HIGH 7.1

    Dell PowerProtect Data Domain contains a stored cross-site scripting (XSS) vulnerability that allows an unauthenticated attacker to inject malicious code into the application. When legitimate users access the affected system, that injected code executes in their browsers, potentially stealing session tokens, harvesting credentials, or performing actions on their behalf. The vulnerability affects multiple release branches across versions 7.7.1.0 through 8.7, with specific ranges identified for LTS releases.

  • CVE-2024-22447MEDIUM 6.7

    Dell Peripheral Manager versions before 1.7.3 contain a vulnerability that allows an attacker with local access to execute arbitrary code by placing a malicious DLL file in a location that the application searches during startup. The flaw stems from the application not properly validating the search path for required libraries, a weakness commonly exploited to hijack legitimate software execution.

  • CVE-2024-22451MEDIUM 6.7

    Dell Peripheral Manager versions 1.5.1 through 1.7.2 contain a vulnerability that allows an attacker with local access to execute arbitrary code by placing malicious files in locations the software searches when loading libraries or executables. An attacker would need valid credentials and user interaction to trigger the exploit, but successful exploitation could give them the same permissions as the user running the affected application.

  • CVE-2026-46732MEDIUM 6.7

    Dell Display and Peripheral Manager (DDPM) for macOS versions before 2.3 contain a race condition vulnerability that allows a low-privileged local user to escalate their privileges on an affected system. A race condition occurs when a program accesses a shared resource in an unsafe manner, allowing an attacker to manipulate the timing or sequence of operations to gain unauthorized access. In this case, the vulnerability requires the attacker to already have local access to the system and user interaction to be exploited, which somewhat limits its attack surface but still represents a meaningful privilege escalation risk.

  • CVE-2026-49813MEDIUM 6.7

    Dell PowerProtect Data Domain, a widely deployed backup and deduplication appliance, contains an OS command injection vulnerability that allows high-privileged local users to execute arbitrary system commands. The vulnerability affects multiple release tracks (standard, LTS2026, LTS2025, and LTS2024) across version ranges from 7.7.1.0 through 8.7. While exploitation requires existing high-level administrative access and local connectivity to the system, successful exploitation could compromise the entire backup infrastructure, including the ability to read, modify, or destroy protected data.

  • CVE-2026-54483MEDIUM 6.7

    Dell PowerProtect Data Domain contains a command injection vulnerability that allows high-privileged local attackers to execute arbitrary commands on affected systems. The flaw exists across multiple release branches (versions 7.7.1.0 through 8.6, including LTS variants from 2024–2026) and stems from improper handling of special characters in OS commands. While the vulnerability requires local access and elevated privileges to exploit, successful compromise could grant complete system control.

  • CVE-2024-47477MEDIUM 6.5

    Dell PowerFlex Manager versions before 4.5.1.1 have a flaw in how they validate SSL/TLS certificates from servers they connect to. An attacker on the network path between a user and PowerFlex Manager could intercept and impersonate the legitimate server, potentially gaining access to sensitive data or modifying communications. The vulnerability requires the attacker to also poison DNS records to redirect traffic, but both techniques are well-established attack vectors that don't require authentication or user interaction.

  • CVE-2026-26355MEDIUM 6.5

    Dell PowerProtect Data Domain contains a command injection flaw that allows attackers with high-level system access to execute arbitrary OS commands remotely. This vulnerability affects multiple release branches (standard, LTS2026, LTS2025, and LTS2024) across a range of versions. While the attacker must already possess elevated privileges, successful exploitation could lead to complete system compromise through command execution.

  • CVE-2026-46463MEDIUM 6.5

    Dell PowerProtect Data Domain, a data protection and deduplication appliance widely deployed in enterprise backup environments, contains a flaw that allows an unauthenticated remote attacker to cause the system to stop responding. The vulnerability stems from improper handling of numeric calculations, which can overflow and trigger unexpected behavior. An attacker does not need valid credentials to attempt exploitation, making this a network-reachable concern for organizations running affected versions.

  • CVE-2026-54468MEDIUM 6.5

    Dell Unisphere for PowerMax versions 10.3.0.5 and earlier contain a flaw that allows an authenticated attacker with basic network access to bypass file path restrictions and read files they should not be able to access. The vulnerability requires valid credentials but does not need user interaction to trigger, making it a concern for organizations with untrusted internal users or compromised service accounts.

  • CVE-2026-40713MEDIUM 6.1

    Dell ThinOS 10 devices running versions before 2602_10.0765 have a flaw that allows someone with physical access to the device—without needing to log in—to view sensitive information stored on it. This is a medium-severity issue because it requires hands-on access to the hardware, but once someone has that access, the controls meant to protect data don't work properly.

  • CVE-2026-44273MEDIUM 6.0

    Dell Wyse Management Suite before version 2605 contains a default credentials vulnerability that allows a high-privileged local user to access sensitive information. An attacker already holding elevated administrative privileges on the system could use hardcoded or default credentials to bypass authentication controls and obtain confidential data stored within the management suite. This is not a network-accessible vulnerability and requires both local system access and high-level privileges to exploit.

  • CVE-2026-46467MEDIUM 5.8

    Dell PowerProtect Data Domain contains a flaw that causes sensitive information to be written to log files where it should not be. An attacker with local system access and limited privileges could read these logs to obtain confidential data. This is a local-access vulnerability—the attacker must already have a foothold on the affected system.

  • CVE-2026-35067MEDIUM 5.7

    Dell PowerFlex Manager versions before 5.1.0.1 contain a flaw in how access is controlled that could allow someone already on your network with limited user privileges to gain higher-level administrative access or view sensitive data they shouldn't see. An attacker would need to be on the same network segment as the system and have at least basic user credentials to attempt this attack.

  • CVE-2026-35069MEDIUM 5.7

    Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection flaw that allows a low-privileged attacker on the same network to inject malicious SQL commands. This could enable script injection attacks, potentially compromising data confidentiality or system integrity depending on the attacker's follow-up actions. The vulnerability requires adjacent network access and valid credentials to exploit, which limits its immediate exposure but remains a real risk in internal environments.

  • CVE-2026-46465MEDIUM 5.5

    Dell PowerProtect Data Domain contains a format string vulnerability that allows a high-privileged attacker with network access to trigger information disclosure or crash the system. While the vulnerability requires elevated privileges to exploit, its presence in backup and archival infrastructure—often a critical dependency—warrants careful monitoring and timely patching.

  • CVE-2026-54470MEDIUM 5.3

    Dell Unisphere for PowerMax versions 10.3.0.5 and earlier contain an XML External Entity (XXE) vulnerability that allows a low-privileged remote attacker to read sensitive data without authorization. The vulnerability is difficult to exploit in practice—it requires valid user credentials and specific conditions—but when successfully exploited, it can expose confidential information stored or processed by the storage management system.

  • CVE-2026-46464MEDIUM 4.9

    Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, along with specific LTS releases (8.6.1.0–8.6.1.10, 8.3.1.0–8.3.1.30, and 7.13.1.0–7.13.1.70), contain a link-following vulnerability that could allow a high-privileged remote attacker to access sensitive information. The flaw stems from improper validation of symbolic links or file path traversal before accessing files on the system. While the attack requires elevated privileges and does not permit system modification or unavailability, the potential for information disclosure in a data protection appliance warrants attention.

  • CVE-2026-40641MEDIUM 4.8

    Dell PowerFlex Manager versions before 5.1.0.1 use weak cryptographic algorithms that could allow remote attackers without credentials to access or modify sensitive data. An attacker would need specific conditions to succeed, but the risk centers on information disclosure and tampering rather than system availability.

  • CVE-2026-44268MEDIUM 4.4

    Dell PowerProtect Data Domain contains a permissions vulnerability that could allow a high-privileged local attacker to read sensitive data. The issue stems from incorrect file or resource permission assignment in affected versions. An attacker with existing administrative or root access could escalate their capabilities to access confidential information they shouldn't be able to reach. This is not a remote vulnerability—it requires someone already on the system with elevated privileges.

  • CVE-2026-44269MEDIUM 4.4

    Dell PowerProtect Data Domain contains a symlink-following vulnerability that allows an attacker with high-level local system access to read sensitive files they shouldn't be able to access. The flaw exists in versions 7.7.1.0 through 8.6, affecting multiple support branches (LTS2026, LTS2025, and LTS2024). While the attacker must already have elevated privileges on the system, the vulnerability could lead to unauthorized disclosure of confidential data stored on the backup appliance.

  • CVE-2026-46468MEDIUM 4.4

    Dell PowerProtect Data Domain contains a vulnerability where the system doesn't properly check symbolic links before accessing files. An attacker with high-level local system access could exploit this to read sensitive information they shouldn't normally access. While the attack requires significant privileges and local access, the potential exposure of confidential data makes this a meaningful security concern for organizations relying on Data Domain for backup and archival operations.

  • CVE-2025-32748MEDIUM 4.3

    Dell PowerFlex Manager versions before 5.1.0.1 contain a host header injection flaw that allows unauthenticated attackers with network access to craft malicious requests. By manipulating the HTTP Host header, an attacker can cause the application to redirect users to arbitrary external websites, potentially in service of phishing or social engineering campaigns. No authentication is required to trigger the vulnerability, but successful exploitation requires user interaction—the victim must follow the malicious redirect.

  • CVE-2026-35162MEDIUM 4.3

    Dell PowerFlex Manager versions before 5.1.0.1 have an access control flaw that allows low-privilege remote users to trigger denial-of-service conditions. While the attacker needs valid credentials, the barrier to exploitation is relatively low, and the impact centers on service availability rather than data compromise.

  • CVE-2026-41123MEDIUM 4.3

    Dell PowerProtect Data Domain contains a flaw in its role-based access control (RBAC) system that allows a low-privileged remote user to modify or tamper with information they shouldn't be able to access. While an attacker cannot read sensitive data or disrupt service availability through this vulnerability, the ability to alter information represents a meaningful integrity risk—particularly critical for a backup and data protection appliance where data trustworthiness is paramount.

  • CVE-2026-46730MEDIUM 4.2

    Dell PowerProtect Data Domain contains an authorization flaw that allows a high-privileged local attacker to execute commands they shouldn't be able to run. The vulnerability affects multiple release branches spanning versions 7.7.1.0 through 8.7, and while it requires someone with elevated access and physical/local connectivity to the system, it could lead to unauthorized actions within the backup infrastructure.

  • CVE-2026-35068LOW 3.5

    Dell PowerFlex Manager versions before 5.1.0.1 contain a SQL injection vulnerability that allows a low-privileged attacker with network access to the same segment to query the database directly and extract sensitive information. While the attacker needs valid credentials and local network access, the flaw bypasses input validation on database commands, potentially exposing configuration data, credentials, or operational metrics stored in PowerFlex deployments.

  • CVE-2026-56085LOW 3.3

    Dell PowerProtect Data Domain contains a vulnerability in how it initializes system resources. An attacker with local access and basic user privileges can read sensitive information from memory that should have been cleared. This is a localized information disclosure issue with limited scope—the attacker cannot modify data or crash the system.

  • CVE-2026-46466LOW 2.7

    Dell PowerProtect Data Domain is vulnerable to a flaw where high-privileged attackers with remote network access can manipulate information on the system. The vulnerability stems from the software trusting data from less reliable sources than it should. This affects multiple versions across different release lines (7.7.1.0–8.7, plus specific LTS versions from 2024–2026). While the flaw requires administrator-level credentials to exploit, organizations relying on Data Domain for backup and deduplication should treat this as a data integrity risk.

  • CVE-2026-53480LOW 2.7

    Dell PowerProtect Data Domain—a backup and deduplication appliance used in enterprise data protection—contains a path traversal vulnerability affecting multiple release branches. An attacker with high-level administrative or service credentials who can reach the device remotely could modify files outside intended directories, potentially altering system behavior or corrupting protected data. The vulnerability is rated LOW severity due to the requirement for elevated privileges and limited immediate impact.

  • CVE-2026-41124LOW 2.3

    Dell PowerProtect Data Domain contains a path traversal vulnerability that allows a high-privileged local attacker to read sensitive files on affected systems. The vulnerability affects multiple versions across four release lines (7.13.1.x, 8.3.1.x, 8.6.1.x, and 7.7.1.0 through 8.6). While the impact is limited to information disclosure and requires both elevated privileges and local access, organizations running these backup appliances should assess their exposure and plan remediation.