LOW 2.7

CVE-2026-46466: Dell PowerProtect Data Domain Information Tampering Vulnerability

Dell PowerProtect Data Domain is vulnerable to a flaw where high-privileged attackers with remote network access can manipulate information on the system. The vulnerability stems from the software trusting data from less reliable sources than it should. This affects multiple versions across different release lines (7.7.1.0–8.7, plus specific LTS versions from 2024–2026). While the flaw requires administrator-level credentials to exploit, organizations relying on Data Domain for backup and deduplication should treat this as a data integrity risk.

Source data · NVD / CISA · public domain

CVSS
3.1 · 2.7 LOW · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Weaknesses (CWE)
CWE-348
Affected products
1 configuration(s)
Published / Modified
2026-07-03 / 2026-07-08

NVD description (verbatim)

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less trusted source vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information tampering.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability (CWE-348: Use of Less Trusted Source) allows a high-privileged remote attacker to tamper with information on affected Dell PowerProtect Data Domain systems. The attack vector is network-based and requires high privileges but no user interaction. The CVSS v3.1 vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N) reflects a low overall score of 2.7, meaning integrity impact is limited and there is no confidentiality or availability loss. The vulnerability exists in Data Domain Operating System versions 7.7.1.0 through 8.7, as well as in LTS2026 (8.6.1.0–8.6.1.10), LTS2025 (8.3.1.0–8.3.1.30), and LTS2024 (7.13.1.0–7.13.1.70) releases.

Business impact

The primary business risk is data integrity compromise on backup and deduplication appliances. PowerProtect Data Domain is typically deployed as a critical backup target; a high-privileged attacker gaining remote access could alter backup metadata, restore points, or configuration information. This could undermine backup reliability and complicate incident response or recovery operations. The low CVSS score reflects that this requires existing high-privilege access, which limits the threat surface significantly. Organizations should assess the likelihood of a compromised admin account within their infrastructure, as well as whether third-party integrations with Data Domain might grant elevated privileges to less-controlled systems.

Affected systems

Dell PowerProtect Data Domain Operating System is affected across a broad version range: mainline versions 7.7.1.0 through 8.7 (inclusive), plus three LTS release streams: LTS2026 (8.6.1.0–8.6.1.10), LTS2025 (8.3.1.0–8.3.1.30), and LTS2024 (7.13.1.0–7.13.1.70). Organizations should verify their exact build version via the Data Domain web interface or CLI before determining exposure. If you are on an unsupported version, the risk is heightened because vendor updates may not be available.

Exploitability

Exploitability is constrained by the requirement for high-privileged credentials. An attacker must first obtain or already possess administrator or equivalent-level access to the Data Domain system to trigger this flaw. The network-based attack vector means the exploit can be performed remotely without physical access, but the high-privilege barrier limits opportunistic attack likelihood. This is not a privilege-escalation vulnerability; it requires pre-existing admin rights. Organizations with strong access controls, multi-factor authentication on administrative accounts, and monitoring of privileged actions should find this risk manageable. However, lateral movement from a compromised workstation with Data Domain management credentials would enable exploitation.

Remediation

Dell has released updates to address this vulnerability. Verify the patched versions against Dell's official security advisory to confirm which releases contain fixes. Organizations should prioritize patching based on their environment's criticality and access control maturity. For systems in highly restricted environments with limited remote admin access, interim risk mitigation includes: restricting network access to Data Domain management interfaces, requiring multi-factor authentication for admin login, and implementing comprehensive audit logging of administrative actions. Patch application is the definitive remediation.

Patch guidance

Consult Dell PowerProtect Data Domain security advisories and product documentation for the specific patched version numbers for each release stream (mainline, LTS2026, LTS2025, LTS2024). Test patches in a non-production environment first, particularly given that Data Domain is often mission-critical to backup operations. Plan patching during a maintenance window to minimize disruption. Verify post-patch operation by confirming system health and backup/deduplication functionality. Maintain backups of the Data Domain configuration before applying updates.

Detection guidance

Monitor Data Domain audit logs for unusual administrative login activity, especially from unexpected IP addresses or outside normal maintenance windows. Track changes to backup policies, deduplication settings, or metadata—these may indicate tampering. Correlate Data Domain admin access logs with endpoint detection systems to identify whether admin credentials were used from compromised workstations. Enable and review authentication logs for failed login attempts and privilege usage. Implement alerting on any modifications to critical backup metadata or recovery points that have no corresponding change request.

Why prioritize this

Although the CVSS score is low (2.7), this vulnerability warrants timely attention because it directly affects data integrity on a system trusted to protect critical backups. The requirement for high privileges reduces urgency compared to pre-auth flaws, but the impact—potential tampering with backup data—could be severe in a post-incident forensics scenario. Prioritize patching based on whether your Data Domain systems are accessible from less-trusted network segments or support integrations with third-party tools that might grant elevated privileges. Low-risk deployments in air-gapped or highly restricted environments may defer patching longer than internet-facing or integration-heavy setups.

Risk score, explained

The CVSS v3.1 score of 2.7 (LOW) reflects that this vulnerability requires high-privilege access and produces only an integrity impact on the local system (no confidentiality loss, no availability loss, no scope change). The network-based attack vector elevates concern somewhat, but the high-privilege prerequisite is a significant mitigating factor. Context matters: in an environment with weak access controls or many admin users, the risk is higher; in a locked-down environment with MFA and minimal admin access, the risk is lower.

Frequently asked questions

Do I need to patch immediately if I am running a Data Domain version in the affected range?

Not necessarily immediately, but within a planned maintenance cycle. Since this requires high-privileged credentials, assess your access controls first. If your Data Domain admin access is tightly restricted and monitored, the risk is lower. However, if many staff have admin rights or remote access is broad, patch sooner. Check Dell's advisory for specific guidance on your version.

Can an attacker use this to escalate from a lower-privilege account?

No. This vulnerability requires the attacker to already have high privileges (administrator level). It is not a privilege-escalation flaw. If an attacker lacks admin credentials, they cannot exploit it.

Does this vulnerability leak backup data or compromise encryption?

No. The vulnerability impacts information tampering (integrity), not confidentiality. Backup encryption and data confidentiality are not affected. The concern is that an attacker with admin access could alter backup metadata or configuration, potentially affecting recovery operations.

If I'm on an older, unsupported version, what should I do?

Unsupported versions should be treated as higher risk because vendors no longer release patches. Plan an upgrade to a currently supported LTS or mainline version, test thoroughly in a lab, and schedule a maintenance window. In the interim, apply compensating controls: restrict network access to the system, require MFA for administration, and increase audit logging.

This analysis is for informational purposes and based on publicly available CVE data current as of the publication date. Organizations should verify all patch version numbers, affected build lists, and remediation guidance directly from Dell's official security advisories before making deployment decisions. Patch testing and deployment timelines should reflect your organization's risk tolerance, change management processes, and business continuity requirements. SEC.co does not provide real-time threat intelligence or exploit availability data; consult threat intelligence platforms and vendor advisories for current threat context. Always validate vulnerability applicability to your specific environment and configuration before implementing changes. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).