CVE-2026-41124: Dell PowerProtect Data Domain Path Traversal (CVSS 2.3)
Dell PowerProtect Data Domain contains a path traversal vulnerability that allows a high-privileged local attacker to read sensitive files on affected systems. The vulnerability affects multiple versions across four release lines (7.13.1.x, 8.3.1.x, 8.6.1.x, and 7.7.1.0 through 8.6). While the impact is limited to information disclosure and requires both elevated privileges and local access, organizations running these backup appliances should assess their exposure and plan remediation.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 2.3 LOW · CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-22
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-08
NVD description (verbatim)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
This path traversal vulnerability (CWE-22) exists in Dell PowerProtect Data Domain across versions 7.7.1.0–8.6, LTS2026 8.6.1.0–8.6.1.10, LTS2025 8.3.1.0–8.3.1.30, and LTS2024 7.13.1.0–7.13.1.70. The flaw permits a local user with high-level privileges to bypass pathname restrictions and access files outside their intended directory scope, potentially exposing sensitive data. The CVSS 3.1 score of 2.3 reflects the limited attack surface: local access requirement, high privilege level needed, and confidentiality impact only (no integrity or availability risk).
Business impact
Information disclosure from a backup appliance can expose configuration data, metadata, or other sensitive content stored on the Data Domain system. While not a direct data exfiltration risk (backups remain intact), exposed information could inform secondary attacks or reveal system topology and credentials. For organizations where Data Domain serves as a critical recovery point, any compromise to its integrity or confidentiality warrants attention—particularly in regulated industries where backup system security is audited.
Affected systems
Dell PowerProtect Data Domain is affected across four distinct release tracks: LTS2024 (7.13.1.0–7.13.1.70), LTS2025 (8.3.1.0–8.3.1.30), LTS2026 (8.6.1.0–8.6.1.10), and the standard line (7.7.1.0–8.6). Organizations should identify which versions they operate in their environment—LTS releases receive longer support windows, so patching timelines may differ by release track.
Exploitability
Exploitation is constrained by two significant factors: the attacker must possess high-level (administrative or equivalent) privileges on the Data Domain system, and they must have local (not remote) access. These prerequisites make opportunistic exploitation unlikely. However, insider threats, lateral movement by a compromised privileged account, or physical access by a malicious administrator represent plausible scenarios in environments where access controls are not strictly enforced.
Remediation
Dell will provide patches for affected versions across all four release tracks. Consult Dell's security advisory for specific patch versions for your release line—do not assume a single patch applies to all versions. Patch testing should occur in a non-production environment first, as Data Domain is often in the critical backup chain. Prioritize LTS2024 and earlier versions for faster deployment if your roadmap permits, as newer LTS releases will receive patches sooner.
Patch guidance
Verify the exact patch version from Dell's official security advisory for your specific Data Domain release. LTS releases (2024, 2025, 2026) will have separate patch versions from the standard release line. Plan patching during a maintenance window; while Data Domain backup appliances are resilient, any downtime affects new backup operations. Test patches in a staging environment with similar configuration and data load to your production system. After patching, confirm that backup jobs execute normally and retention policies are unaffected.
Detection guidance
Monitor local login events and privileged user activity on Data Domain systems (authentication logs, syslog, audit trails). Look for unusual file access patterns or command execution outside normal backup operations, particularly attempts to traverse directories using relative paths ("../") or symbolic links. Network segmentation can help limit lateral movement if a privileged account on another system becomes compromised. Consider implementing application-level controls that restrict directory traversal attempts at the Data Domain OS level if Dell provides configuration hardening options.
Why prioritize this
Although the CVSS score is low (2.3), the vulnerability should not be dismissed. Path traversal on a backup system poses indirect but meaningful risk: exposed metadata or configurations could enable larger infrastructure attacks. The requirement for high privileges and local access significantly reduces the threat surface, making this a medium-term remediation priority rather than an emergency. Organizations with strict access controls and segmented networks can operate safely while planning patches; those with weaker privilege management or public-facing Data Domain systems should prioritize sooner.
Risk score, explained
The CVSS 3.1 score of 2.3 (LOW) reflects the restricted attack profile: local access only (AV:L), high privilege requirement (PR:H), no user interaction needed (UI:N), and confidentiality impact limited to the local system scope (C:L, I:N, A:N). This is not a network-exploitable vulnerability and does not allow privilege escalation or denial of service. The score appropriately captures that while the flaw is real, the real-world risk is constrained by access prerequisites.
Frequently asked questions
Do we need to patch immediately?
No. This is a LOW-severity vulnerability requiring both local access and high privileges. If your Data Domain system is properly network-segmented and access is restricted to authorized administrators, you can plan patching within your normal change window (next 30–90 days). Immediate action is warranted only if you have evidence of unauthorized access or suspect a compromised privileged account.
Can an external attacker exploit this remotely?
No. The vulnerability requires local access and high-level privileges. Remote attackers cannot directly exploit it. However, if an attacker gains remote code execution on another system or compromises a privileged user account with login access to Data Domain, they could then exploit this flaw locally.
Does this affect the security of my backups themselves?
No. This vulnerability allows reading files on the Data Domain operating system, not modifying or deleting backups. Your backup data integrity is not at risk. However, exposed metadata or system configurations could indirectly inform attacks on your broader infrastructure.
Which versions should we patch first?
Prioritize the oldest LTS releases first (LTS2024: 7.13.1.0–7.13.1.70, then LTS2025, then LTS2026) since they will reach end-of-support sooner. Verify exact patch versions from Dell's advisory; patches are release-specific and cannot be cross-applied.
This analysis is provided for educational and risk assessment purposes. Patch version numbers, vendor release dates, and specific remediation steps must be verified against Dell's official security advisory before implementation. SEC.co does not provide real-time vulnerability feeds or guarantee completeness of affected version information. Organizations should validate their specific product versions, configurations, and support entitlements with Dell directly. This is not a substitute for professional security assessment or vendor support. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-53480LOWDell PowerProtect Data Domain Path Traversal Vulnerability
- CVE-2026-49506HIGHDell Wyse Management Suite Path Traversal & Remote Code Execution
- CVE-2026-54468MEDIUMDell Unisphere for PowerMax Path Traversal Vulnerability
- CVE-2026-10264LOWPath Traversal in lharries whatsapp-mcp 0.0.1
- CVE-2026-12211LOWIntelbras iNVU 7016 FT Path Traversal Vulnerability Analysis
- CVE-2026-14967LOWBBOT Path Traversal in GitHub Workflows Module—Low-Risk Artifact Write Bypass
- CVE-2026-15326LOWHalo Path Traversal in Theme Installation (CWE-22)
- CVE-2026-45380LOWOff-by-One Path Traversal in bit7z Archive Extraction