CVE-2026-26355 Dell PowerProtect Data Domain OS Command Injection Vulnerability
Dell PowerProtect Data Domain contains a command injection flaw that allows attackers with high-level system access to execute arbitrary OS commands remotely. This vulnerability affects multiple release branches (standard, LTS2026, LTS2025, and LTS2024) across a range of versions. While the attacker must already possess elevated privileges, successful exploitation could lead to complete system compromise through command execution.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 6.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- Weaknesses (CWE)
- CWE-78
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-08
NVD description (verbatim)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-26355 is an OS command injection vulnerability (CWE-78) in Dell PowerProtect Data Domain stemming from improper neutralization of special characters in command construction. The vulnerability exists in versions 7.7.1.0 through 8.7 (standard release), 8.6.1.0 through 8.6.1.10 (LTS2026), 8.3.1.0 through 8.3.1.30 (LTS2025), and 7.13.1.0 through 7.13.1.70 (LTS2024). An attacker with high privilege context and network access can inject OS commands through an unvalidated input vector, resulting in arbitrary command execution with the privileges of the running process. The CVSS 3.1 score of 6.5 (MEDIUM) reflects the requirement for high-privilege access (PR:H) as a mitigating factor, though integrity and availability impacts are rated high once exploited.
Business impact
Unauthorized command execution on Data Domain systems could lead to data exfiltration, system manipulation, or denial of service—critical concerns for backup and disaster recovery infrastructure. Since Data Domain is a deduplication appliance handling sensitive backup data, a compromised instance could expose protected data across multiple protected environments. The requirement for high-privilege access limits exposure to insider threats and compromised administrative accounts, but does not eliminate risk in multi-tenant or federated environments.
Affected systems
Dell PowerProtect Data Domain is affected across multiple release tracks: standard versions 7.7.1.0–8.7, LTS2026 versions 8.6.1.0–8.6.1.10, LTS2025 versions 8.3.1.0–8.3.1.30, and LTS2024 versions 7.13.1.0–7.13.1.70. Organizations running any of these versions should audit their deployment scope. Verify your exact version against the Data Domain system interface or administrative tooling before assuming patched status.
Exploitability
Exploitation requires high-privileged attacker access and network connectivity to the vulnerable system. These preconditions reduce opportunistic exploitation risk compared to unauthenticated vulnerabilities. However, threat actors with access to compromised administrative credentials—via phishing, lateral movement, or third-party compromise—could weaponize this flaw. The CVSS vector reflects no additional complexity (AC:L) once authentication is achieved. This remains a realistic risk in environments with inadequate credential hygiene or privileged account segmentation.
Remediation
Dell has issued patches for all affected release branches. Organizations must identify which Data Domain versions are deployed, cross-reference against Dell's published fix versions for each release track, and apply patches according to their change management schedule. Given the high-privilege requirement, interim compensating controls—such as restricting administrative access, enforcing multi-factor authentication for privileged accounts, and network segmentation of Data Domain systems—can reduce exploitation likelihood while patches are validated and deployed.
Patch guidance
Contact Dell support or consult Dell's security advisory for CVE-2026-26355 to obtain the specific patched version numbers for each affected release branch (standard, LTS2026, LTS2025, LTS2024). Patch availability and release dates vary by branch. Test patches in a non-production environment before deploying to production backup systems to ensure compatibility with your backup workflows and any third-party integrations. Document pre- and post-patch system health metrics.
Detection guidance
Monitor Data Domain system logs for unusual OS command execution, particularly commands invoked through administrative interfaces or API endpoints. Look for evidence of command injection syntax (shell metacharacters, pipe operators, or redirection symbols) in audit logs or error messages. Implement file integrity monitoring on critical system binaries and configuration files. Network-based detection should focus on anomalous administrative API calls or authentication patterns from unexpected sources. Consider deploying Data Domain-specific SIEM rules or enabling enhanced logging if available in your version.
Why prioritize this
Although rated MEDIUM severity, this vulnerability warrants prioritization in environments where Data Domain systems handle sensitive or regulatory-protected backup data. The high-privilege requirement and lack of CISA KEV designation reduce immediate exploitation urgency, but the potential for data breach through a compromised administrative account—combined with the centralized, high-value nature of backup infrastructure—justifies treating this as high-impact in your risk context. Organizations with mature administrative access controls and MFA can deprioritize relative to unauthenticated vulnerabilities; those without should accelerate patching.
Risk score, explained
The CVSS 3.1 score of 6.5 reflects a MEDIUM severity rating driven by the requirement for high-privilege attacker status (PR:H), which significantly reduces the attack surface. However, this score does not capture the business criticality of Data Domain systems themselves—backup infrastructure that, if compromised, can undermine recovery capabilities organization-wide. The integrity (I:H) and availability (A:H) impacts mean that successful exploitation has severe consequences. Risk context (not just CVSS) should include the sensitivity of protected data, administrative access control maturity, and recovery time objectives.
Frequently asked questions
Does this vulnerability require the attacker to already have an account or be authenticated?
Yes. The CVSS vector indicates PR:H (High Privilege Required), meaning the attacker must already possess high-level administrative or system credentials. This is not an unauthenticated remote code execution—it targets insider threats or compromised administrative accounts.
How do I know if my Data Domain system is vulnerable?
Log into your Data Domain administrative interface and identify your current version (typically displayed on the dashboard or via CLI). Cross-reference your exact version number against the vulnerability description's affected ranges for your release branch (standard, LTS2026, LTS2025, or LTS2024). If your version falls within any of the stated ranges, you are vulnerable until patched.
What's the difference between these release branches (LTS2026, LTS2025, etc.)?
Dell PowerProtect Data Domain offers both a standard rolling-release track and long-term support (LTS) branches with extended security support windows. Different branches have different patched versions, so you must identify which branch you are on before seeking patches. Consult Dell's advisory or support to find the patch version applicable to your branch.
Can I safely ignore this if I have strong controls on administrative access?
Controls such as multi-factor authentication, privileged account monitoring, and network segmentation substantially reduce risk. However, these are compensating controls, not replacements for patching. A confirmed administrative credential compromise could still enable exploitation. Patch as soon as feasible within your change management window.
This analysis is provided for informational purposes to help security teams contextualize and prioritize vulnerability response. It is not a substitute for vendor advisories or official patch guidance. Verify all version numbers, patch availability, and compatibility against Dell's official security bulletin before deployment. Exploitation in live environments without authorization is illegal. Organizations should validate patches in test environments before production deployment and ensure business continuity during patching windows. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-49813MEDIUMDell PowerProtect Data Domain OS Command Injection Vulnerability
- CVE-2026-54483MEDIUMDell PowerProtect Data Domain OS Command Injection – Patch Guidance
- CVE-2026-49814HIGHDell PowerProtect Data Domain OS Command Injection (CVSS 7.2)
- CVE-2026-49815HIGHDell PowerProtect Data Domain OS Command Injection (CVSS 7.2)
- CVE-2026-53478HIGHDell PowerProtect Data Domain OS Command Injection Vulnerability
- CVE-2026-53479HIGHDell PowerProtect Data Domain OS Command Injection Vulnerability
- CVE-2026-10279MEDIUMOS Command Injection in wezterm-mcp 0.1.0
- CVE-2026-10544MEDIUMDevolutions Server PAM Command Injection Vulnerability