MEDIUM 5.5

CVE-2026-46465: Dell PowerProtect Data Domain Format String Vulnerability (CVSS 5.5)

Dell PowerProtect Data Domain contains a format string vulnerability that allows a high-privileged attacker with network access to trigger information disclosure or crash the system. While the vulnerability requires elevated privileges to exploit, its presence in backup and archival infrastructure—often a critical dependency—warrants careful monitoring and timely patching.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.5 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H
Weaknesses (CWE)
CWE-134
Affected products
1 configuration(s)
Published / Modified
2026-07-03 / 2026-07-08

NVD description (verbatim)

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of externally-controlled format string vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46465 is a CWE-134 (use of externally-controlled format string) vulnerability in Dell PowerProtect Data Domain. Affected versions span multiple release branches: standard support versions 7.7.1.0–8.7, LTS2026 releases 8.6.1.0–8.6.1.10, LTS2025 releases 8.3.1.0–8.3.1.30, and LTS2024 releases 7.13.1.0–7.13.1.70. The vulnerability allows a high-privileged remote attacker to supply a specially crafted format string input that reads or corrupts memory, resulting in information disclosure or denial of service. The CVSS 3.1 score of 5.5 reflects the high privilege requirement (PR:H) combined with measurable confidentiality and availability impacts.

Business impact

PowerProtect Data Domain is commonly deployed as a deduplication and archival platform in enterprise backup environments. Exploitation could result in exposure of sensitive backup metadata or restore failures, compromising recovery capabilities during incident response or data restoration scenarios. The denial-of-service component poses operational risk to backup windows and recovery time objectives (RTO).

Affected systems

Dell PowerProtect Data Domain installations across four active release branches are affected. Organizations should identify instances running any version from 7.7.1.0 through 8.7 in standard support, or any LTS2024, LTS2025, or LTS2026 version within their respective vulnerable ranges. Both on-premises and cloud-deployed instances require assessment.

Exploitability

The attack requires high privilege (administrative or equivalent role) and remote network access, which significantly constrains real-world attack scenarios. An insider threat with legitimate administrative credentials or an attacker who has compromised an administrative account represents the primary risk vector. The absence of user interaction (UI:N) means the attack can be automated once privilege is obtained. Exploit code has not been observed in public repositories or security research disclosures as of the publication date.

Remediation

Dell has released patches for all affected release branches. Verify the specific patched version available for your release branch by consulting Dell's security advisory. Standard support versions should be updated to a patched release beyond 8.7; LTS2026 users should target a patched version beyond 8.6.1.10; LTS2025 users should target beyond 8.3.1.30; and LTS2024 users should target beyond 7.13.1.70. Validate patch availability against your vendor advisory before scheduling maintenance.

Patch guidance

Obtain the latest security patches from Dell's support portal aligned with your deployment's release branch. Plan patching during scheduled maintenance windows, as updates typically require service restarts. Test patches in a pre-production environment to confirm compatibility with your backup workflows and any third-party integrations. For LTS customers, verify that the patched version remains within your long-term support commitment before deploying.

Detection guidance

Monitor PowerProtect Data Domain logs for suspicious format string payloads in remote procedure calls or API inputs, particularly those containing unusual escape sequences (%x, %s, %n) from privileged users. Implement network segmentation to restrict administrative access to Data Domain interfaces. Enable detailed audit logging for all privileged operations and review access logs for unexpected administrative activity. Organizations using SIEM solutions can correlate authentication events with API calls exhibiting format string characteristics.

Why prioritize this

Although the CVSS score is moderate (5.5) and exploitation requires high privilege, the criticality of backup infrastructure in business continuity planning elevates the risk. A successful attack could undermine data recovery capabilities during an active incident, compounding the impact of the primary breach or failure. The broad version range affected and the presence of LTS releases mean many organizations likely carry this vulnerability in production. Prioritize patching if your environment has strict network isolation of administrative access; consider it routine if administrative interface exposure is possible.

Risk score, explained

The CVSS 3.1 score of 5.5 reflects a medium severity rating driven by the high privilege prerequisite (PR:H), which substantially mitigates risk in well-segmented networks. However, the confidentiality impact (partial information disclosure) and high availability impact (denial of service) indicate measurable harm if exploited. The network-accessible nature (AV:N) ensures the vulnerability is not purely local. Organizations should weight this score against their specific threat model: those with strong privilege boundaries and administrative access controls may assess risk lower, while those with permissive internal trust models should assess risk higher.

Frequently asked questions

Does this vulnerability appear on CISA's Known Exploited Vulnerabilities (KEV) catalog?

No. As of the publication date, CVE-2026-46465 has not been added to CISA's KEV catalog, indicating no confirmed public exploitation or weaponized proof-of-concept code has emerged. Continued monitoring of threat intelligence feeds is recommended to detect any shift in this status.

What is the difference between the standard support and LTS release branches, and does it affect my patching strategy?

Standard support versions follow a continuous release cycle and receive security updates in newer versions (e.g., beyond 8.7). LTS (Long-Term Support) releases are fixed feature versions that receive patches within their branch (e.g., LTS2024 receives updates up to 7.13.1.70). Identify your deployment's branch in Dell's system information, then locate the appropriate patched version for that branch to ensure you remain within your support contract.

If our PowerProtect Data Domain is isolated to the internal network with strict firewall rules, how urgent is this patch?

Network isolation significantly reduces exposure, since the attack requires high privilege and remote access. If administrative interfaces are restricted to a limited set of trusted IPs and accessible only by a small number of staff, the risk is substantially lower. However, patch when feasible to eliminate the vulnerability entirely and protect against compromised internal credentials or lateral movement by an attacker already inside your network.

What should we do if we cannot patch immediately due to system stability concerns?

Implement compensating controls: restrict network access to the administrative interface using firewall rules, disable remote administration if not actively required, enforce multi-factor authentication for administrative accounts, and increase monitoring of administrative actions via audit logs and SIEM. Document the risk acceptance and establish a target date for patching. Contact Dell support to discuss any known stability issues with the patched release for your version.

This analysis is provided for informational purposes only and does not constitute security advice. Patch versions, release timelines, and vendor advisories are subject to change; always verify the latest information directly from Dell's official security resources. The assessment of risk and exploitability assumes a standard enterprise environment and does not account for unique organizational factors, network topologies, or threat models. Organizations are responsible for conducting their own vulnerability assessments and determining patching priorities based on their specific operational context and risk tolerance. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).