CVE-2026-41123: Dell PowerProtect Data Domain RBAC Access Control Vulnerability
Dell PowerProtect Data Domain contains a flaw in its role-based access control (RBAC) system that allows a low-privileged remote user to modify or tamper with information they shouldn't be able to access. While an attacker cannot read sensitive data or disrupt service availability through this vulnerability, the ability to alter information represents a meaningful integrity risk—particularly critical for a backup and data protection appliance where data trustworthiness is paramount.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-08
NVD description (verbatim)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-41123 is an improper access control vulnerability (CWE-284) affecting Dell PowerProtect Data Domain's RBAC implementation. The vulnerability permits authenticated users with low privilege levels to perform unauthorized modifications to protected data or configurations. The CVSS 3.1 score of 4.3 reflects a network-accessible attack requiring valid credentials, with limited impact scope (integrity only, no confidentiality or availability compromise). The flaw spans multiple release branches: standard versions 7.7.1.0–8.6, LTS2026 8.6.1.0–8.6.1.10, LTS2025 8.3.1.0–8.3.1.30, and LTS2024 7.13.1.0–7.13.1.70.
Business impact
For organizations relying on Data Domain for backup and deduplication, this vulnerability introduces data integrity risk. An insider or compromised account with basic system access could alter backup metadata, restore points, or configuration parameters without proper authorization. While the attack requires network access and valid credentials, the impact is particularly concerning because: (1) Data Domain is often trusted as a recovery system; (2) integrity tampering might not be immediately visible in logs; (3) corrupted or altered backups could undermine recovery objectives during an actual incident response.
Affected systems
Dell PowerProtect Data Domain operating system versions 7.7.1.0 through 8.6, plus all three LTS branches (LTS2024, LTS2025, LTS2026) are affected. Organizations should verify their exact Data Domain firmware version in the system dashboard or via CLI to determine exposure. This covers both current-release and long-term-support tracks, so both modernly-updated and stability-focused deployments require attention.
Exploitability
Exploitation requires valid user credentials and network access to the Data Domain management interface. The attack complexity is low—no special conditions or race conditions are needed once authenticated. However, the requirement for pre-existing access substantially reduces the likelihood of remote, unauthenticated exploitation. The vulnerability does not appear in the CISA KEV catalog, indicating no evidence of active exploitation in the wild as of the publication date. Organizations should still prioritize remediation for environments where user account hygiene is loose or where service accounts have overly broad permissions.
Remediation
Dell has issued patches across all affected release branches. Organizations should apply vendor-supplied firmware updates immediately upon availability, which will address the RBAC control gaps. Interim mitigations include: (1) restricting network access to Data Domain management interfaces via firewall rules; (2) auditing RBAC role assignments and reducing privileges to only what is necessary; (3) enabling and monitoring Data Domain audit logs for suspicious data modifications; (4) implementing multi-factor authentication for administrative access if supported by your Data Domain version.
Patch guidance
Check Dell's security advisories and Data Domain release notes for patched firmware versions corresponding to your current release branch. Patches are expected for versions 7.7.1.0–8.6, LTS2024 (7.13.1.x), LTS2025 (8.3.1.x), and LTS2026 (8.6.1.x). Verify against the vendor advisory the exact patched version number for your branch before upgrading. Data Domain firmware updates typically require a maintenance window; coordinate with backup operations teams to ensure no active backup jobs are running during the patch. Test the patched version in a non-production environment if possible to confirm no regression in deduplication or replication functionality.
Detection guidance
Monitor Data Domain audit logs for unauthorized modification attempts or privilege escalation indicators. Look for: (1) low-privileged users performing administrative-level data modifications; (2) unexpected changes to backup metadata, retention policies, or configuration parameters; (3) role or permission changes that do not correspond to documented administrative actions. Enable verbose logging for RBAC-related events if available. Correlate Data Domain audit events with authentication logs and user provisioning systems to identify anomalous account behavior. Periodic integrity checks on critical backup metadata and restore-point validity can help detect tampering after the fact.
Why prioritize this
Although the CVSS score is moderate (4.3) and no active exploitation is documented, this vulnerability affects a critical system type—backup infrastructure. Data integrity breaches are often discovered late, and corrupted backups can render a critical recovery mechanism ineffective during a security incident. The requirement for authentication limits rapid spread, but the integrity impact justifies prompt attention. Organizations with robust backup governance and strong RBAC hygiene can schedule patching within standard maintenance windows; those with looser access controls or where Data Domain is internet-facing should prioritize higher.
Risk score, explained
The CVSS 3.1 base score of 4.3 (MEDIUM) reflects the vulnerability's limited attack surface: network accessible but requiring authenticated access (PR:L), low attack complexity, and integrity impact only. The score does not account for the asset criticality (backup systems are high-value targets) or the difficulty of detecting tampering retroactively. For environments where data integrity is paramount or where user account proliferation is high, internal risk models should consider elevating the priority above the base CVSS score.
Frequently asked questions
What can an attacker actually do with this vulnerability?
An attacker with valid low-privileged credentials can modify data or settings they shouldn't be able to access via the RBAC system. This includes potential tampering with backup metadata, configuration parameters, or other stored information. Importantly, they cannot read confidential data or shut down the system through this flaw alone.
Do I need to patch immediately if Data Domain isn't internet-facing?
Not necessarily, but you should still prioritize it. If Data Domain is strictly accessible from a trusted internal network with controlled user populations and strong authentication practices, you have some operational flexibility. However, if user accounts are numerous, stored credentials are in use, or if there's any path for lateral movement, patch sooner rather than later.
Is this vulnerability being exploited in the wild?
No. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog as of July 2026, meaning there is no public evidence of active attacks leveraging this flaw. However, lack of documented exploitation does not mean the risk is negligible—backup systems remain high-value targets for sophisticated adversaries.
What if we can't patch immediately due to business constraints?
Implement network segmentation to restrict access to the Data Domain management interface. Audit and reduce RBAC role assignments to eliminate unnecessary privileges. Enable verbose audit logging and monitor for suspicious modifications. If possible, implement multi-factor authentication for administrative access. These interim steps substantially reduce exploitation probability while you plan a maintenance window.
This analysis is provided for informational purposes by SEC.co and does not constitute professional security advice. Organizations must verify all patch versions, affected product versions, and remediation steps against official Dell security advisories before implementing any changes. CVSS scores and vulnerability classifications are based on publicly available information as of the publication date and may be subject to revision. Test all patches in non-production environments before deployment. Consult with your backup and recovery team before scheduling any Data Domain firmware updates. SEC.co makes no warranty regarding the completeness or accuracy of this analysis. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35067MEDIUMDell PowerFlex Manager Privilege Escalation Vulnerability
- CVE-2026-35162MEDIUMDell PowerFlex Manager Access Control Denial of Service
- CVE-2026-40713MEDIUMDell ThinOS 10 Improper Access Control – Patch Guide
- CVE-2026-35066HIGHDell PowerFlex Manager Improper Access Control – DoS Vulnerability
- CVE-2026-40715HIGHDell ThinOS 10 Privilege Escalation Vulnerability
- CVE-2026-46461HIGHDell Server Hardware Manager Privilege Escalation (v3.2.2)
- CVE-2026-46733HIGHDell DDPM Windows Access Control Privilege Escalation – Patch Now
- CVE-2024-27891MEDIUMArista EOS MACsec + Egress ACL Policy Enforcement Failure