MEDIUM 4.3

CVE-2026-41123: Dell PowerProtect Data Domain RBAC Access Control Vulnerability

Dell PowerProtect Data Domain contains a flaw in its role-based access control (RBAC) system that allows a low-privileged remote user to modify or tamper with information they shouldn't be able to access. While an attacker cannot read sensitive data or disrupt service availability through this vulnerability, the ability to alter information represents a meaningful integrity risk—particularly critical for a backup and data protection appliance where data trustworthiness is paramount.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-07-03 / 2026-07-08

NVD description (verbatim)

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-41123 is an improper access control vulnerability (CWE-284) affecting Dell PowerProtect Data Domain's RBAC implementation. The vulnerability permits authenticated users with low privilege levels to perform unauthorized modifications to protected data or configurations. The CVSS 3.1 score of 4.3 reflects a network-accessible attack requiring valid credentials, with limited impact scope (integrity only, no confidentiality or availability compromise). The flaw spans multiple release branches: standard versions 7.7.1.0–8.6, LTS2026 8.6.1.0–8.6.1.10, LTS2025 8.3.1.0–8.3.1.30, and LTS2024 7.13.1.0–7.13.1.70.

Business impact

For organizations relying on Data Domain for backup and deduplication, this vulnerability introduces data integrity risk. An insider or compromised account with basic system access could alter backup metadata, restore points, or configuration parameters without proper authorization. While the attack requires network access and valid credentials, the impact is particularly concerning because: (1) Data Domain is often trusted as a recovery system; (2) integrity tampering might not be immediately visible in logs; (3) corrupted or altered backups could undermine recovery objectives during an actual incident response.

Affected systems

Dell PowerProtect Data Domain operating system versions 7.7.1.0 through 8.6, plus all three LTS branches (LTS2024, LTS2025, LTS2026) are affected. Organizations should verify their exact Data Domain firmware version in the system dashboard or via CLI to determine exposure. This covers both current-release and long-term-support tracks, so both modernly-updated and stability-focused deployments require attention.

Exploitability

Exploitation requires valid user credentials and network access to the Data Domain management interface. The attack complexity is low—no special conditions or race conditions are needed once authenticated. However, the requirement for pre-existing access substantially reduces the likelihood of remote, unauthenticated exploitation. The vulnerability does not appear in the CISA KEV catalog, indicating no evidence of active exploitation in the wild as of the publication date. Organizations should still prioritize remediation for environments where user account hygiene is loose or where service accounts have overly broad permissions.

Remediation

Dell has issued patches across all affected release branches. Organizations should apply vendor-supplied firmware updates immediately upon availability, which will address the RBAC control gaps. Interim mitigations include: (1) restricting network access to Data Domain management interfaces via firewall rules; (2) auditing RBAC role assignments and reducing privileges to only what is necessary; (3) enabling and monitoring Data Domain audit logs for suspicious data modifications; (4) implementing multi-factor authentication for administrative access if supported by your Data Domain version.

Patch guidance

Check Dell's security advisories and Data Domain release notes for patched firmware versions corresponding to your current release branch. Patches are expected for versions 7.7.1.0–8.6, LTS2024 (7.13.1.x), LTS2025 (8.3.1.x), and LTS2026 (8.6.1.x). Verify against the vendor advisory the exact patched version number for your branch before upgrading. Data Domain firmware updates typically require a maintenance window; coordinate with backup operations teams to ensure no active backup jobs are running during the patch. Test the patched version in a non-production environment if possible to confirm no regression in deduplication or replication functionality.

Detection guidance

Monitor Data Domain audit logs for unauthorized modification attempts or privilege escalation indicators. Look for: (1) low-privileged users performing administrative-level data modifications; (2) unexpected changes to backup metadata, retention policies, or configuration parameters; (3) role or permission changes that do not correspond to documented administrative actions. Enable verbose logging for RBAC-related events if available. Correlate Data Domain audit events with authentication logs and user provisioning systems to identify anomalous account behavior. Periodic integrity checks on critical backup metadata and restore-point validity can help detect tampering after the fact.

Why prioritize this

Although the CVSS score is moderate (4.3) and no active exploitation is documented, this vulnerability affects a critical system type—backup infrastructure. Data integrity breaches are often discovered late, and corrupted backups can render a critical recovery mechanism ineffective during a security incident. The requirement for authentication limits rapid spread, but the integrity impact justifies prompt attention. Organizations with robust backup governance and strong RBAC hygiene can schedule patching within standard maintenance windows; those with looser access controls or where Data Domain is internet-facing should prioritize higher.

Risk score, explained

The CVSS 3.1 base score of 4.3 (MEDIUM) reflects the vulnerability's limited attack surface: network accessible but requiring authenticated access (PR:L), low attack complexity, and integrity impact only. The score does not account for the asset criticality (backup systems are high-value targets) or the difficulty of detecting tampering retroactively. For environments where data integrity is paramount or where user account proliferation is high, internal risk models should consider elevating the priority above the base CVSS score.

Frequently asked questions

What can an attacker actually do with this vulnerability?

An attacker with valid low-privileged credentials can modify data or settings they shouldn't be able to access via the RBAC system. This includes potential tampering with backup metadata, configuration parameters, or other stored information. Importantly, they cannot read confidential data or shut down the system through this flaw alone.

Do I need to patch immediately if Data Domain isn't internet-facing?

Not necessarily, but you should still prioritize it. If Data Domain is strictly accessible from a trusted internal network with controlled user populations and strong authentication practices, you have some operational flexibility. However, if user accounts are numerous, stored credentials are in use, or if there's any path for lateral movement, patch sooner rather than later.

Is this vulnerability being exploited in the wild?

No. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog as of July 2026, meaning there is no public evidence of active attacks leveraging this flaw. However, lack of documented exploitation does not mean the risk is negligible—backup systems remain high-value targets for sophisticated adversaries.

What if we can't patch immediately due to business constraints?

Implement network segmentation to restrict access to the Data Domain management interface. Audit and reduce RBAC role assignments to eliminate unnecessary privileges. Enable verbose audit logging and monitor for suspicious modifications. If possible, implement multi-factor authentication for administrative access. These interim steps substantially reduce exploitation probability while you plan a maintenance window.

This analysis is provided for informational purposes by SEC.co and does not constitute professional security advice. Organizations must verify all patch versions, affected product versions, and remediation steps against official Dell security advisories before implementing any changes. CVSS scores and vulnerability classifications are based on publicly available information as of the publication date and may be subject to revision. Test all patches in non-production environments before deployment. Consult with your backup and recovery team before scheduling any Data Domain firmware updates. SEC.co makes no warranty regarding the completeness or accuracy of this analysis. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).