CVE-2026-46467: Dell PowerProtect Data Domain Log Information Disclosure
Dell PowerProtect Data Domain contains a flaw that causes sensitive information to be written to log files where it should not be. An attacker with local system access and limited privileges could read these logs to obtain confidential data. This is a local-access vulnerability—the attacker must already have a foothold on the affected system.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.8 MEDIUM · CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
- Weaknesses (CWE)
- CWE-532
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-07-03 / 2026-07-08
NVD description (verbatim)
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46467 is an information disclosure vulnerability (CWE-532: Insertion of Sensitive Information into Log File) affecting Dell PowerProtect Data Domain. The vulnerability exists in versions 7.7.1.0–8.7 (standard release), LTS2026 8.6.1.0–8.6.1.10, LTS2025 8.3.1.0–8.3.1.30, and LTS2024 7.13.1.0–7.13.1.70. A low-privileged local user can exploit a high-attack-complexity condition to read sensitive data from application logs, resulting in partial confidentiality breach and minimal integrity and availability impact. The CVSS 3.1 score of 5.8 reflects the local-access requirement and limited scope.
Business impact
Data Domain appliances function as deduplication and backup targets in enterprise storage environments. Log-based credential or configuration disclosure could enable lateral movement or persistence within backup infrastructure, potentially compromising data restoration workflows or exposing encryption keys and administrative credentials. The impact is containable because exploitation requires prior local access, but organizations running sensitive backup jobs should treat credential exposure seriously.
Affected systems
All supported versions of Dell PowerProtect Data Domain are affected, spanning multiple release trains: the current standard line (7.7.1.0–8.7), LTS2026 (8.6.1.x), LTS2025 (8.3.1.x), and LTS2024 (7.13.1.x). Organizations should verify exact version numbers in their environments; patch availability will be announced via Dell security advisories.
Exploitability
Exploitability is low in practice despite a CVSS score of 5.8. The attacker must already possess local system access with unprivileged credentials and must satisfy a high attack complexity condition (likely specific system state or configuration). This is not remotely exploitable and does not grant unauthenticated access. Risk is highest in environments where untrusted users have shell or service accounts on Data Domain systems.
Remediation
Dell will issue security patches for all affected version branches. Customers should prioritize patching systems that handle sensitive backup data or where local user access controls are weaker. Verify patch availability against Dell's security advisories before implementing. Where patching is delayed, restrict local access to Data Domain systems and review log file permissions to reduce exposure window.
Patch guidance
Consult Dell's official security advisory for CVE-2026-46467 to identify available patch versions for your release branch (standard, LTS2026, LTS2025, or LTS2024). Test patches in a non-production environment first, as Data Domain patches may require system downtime or appliance reboot. Coordinate patching with your backup maintenance windows to avoid service disruption. Dell typically provides cumulative security updates; apply the latest available patch for your branch rather than patching incrementally.
Detection guidance
Monitor Data Domain systems for unauthorized local login attempts or privilege escalation activities by scanning authentication logs and system audit trails. If available, enable enhanced logging on the appliance and review log files for evidence of unusual access patterns or credential-like strings being logged where they should not be. Correlate Data Domain audit logs with identity and access management (IAM) systems to detect anomalous user behavior. After patching, verify that sensitive data (credentials, encryption keys) is no longer present in standard log outputs.
Why prioritize this
Although the CVSS score is moderate (5.8), prioritization depends on environment. If Data Domain instances are exposed to untrusted local users or if backup infrastructure security posture is weak, patch sooner. If systems are in hardened, segregated networks with strict access controls, patching can follow a standard maintenance cycle. The lack of KEV (Known Exploited Vulnerabilities) designation indicates no widespread active exploitation as of the published date, reducing urgency relative to critical remote-access vulnerabilities.
Risk score, explained
The CVSS 3.1 base score of 5.8 (Medium severity) reflects: Local attack vector (AV:L) due to privilege requirement; high attack complexity (AC:H) implying a non-obvious exploitation path; low privilege level (PR:L) allowing unprivileged users; unchanged scope (S:U); high confidentiality impact (C:H); low integrity impact (I:L); and low availability impact (A:L). The score appropriately captures a credential-disclosure risk that is meaningful but not critical, since remote exploitation is impossible and defender access controls can significantly reduce likelihood.
Frequently asked questions
Could this vulnerability be exploited remotely?
No. CVE-2026-46467 requires local system access; it cannot be exploited over the network. An attacker must first gain a shell, service account, or unprivileged login on the Data Domain appliance itself.
What exactly is being leaked to logs?
The vulnerability causes sensitive information (likely credentials, encryption keys, or configuration secrets) to be written to log files that a low-privileged user can read. The specific data type is detailed in Dell's security advisory; verify there for your use case.
If we are current on patches, are we protected?
Yes, once Dell releases and you apply the patched versions, the log insertion flaw will be fixed. Ensure you update to versions released by Dell as security patches, not just general maintenance releases.
Does this affect our disaster recovery posture?
Not directly, but if backup appliance credentials are compromised via this flaw, an attacker could potentially interfere with restore operations or exfiltrate backed-up data. Segregating Data Domain networks and limiting local access reduces this residual risk.
This analysis is for informational purposes and reflects publicly available information as of the publication date. Patch versions, availability dates, and detailed remediation steps are subject to change and should be verified against Dell's official security advisories. Organizations should conduct their own risk assessment based on environment, threat model, and business criticality. SEC.co and its analysts disclaim liability for decisions made based on this content. Source: NVD (public-domain), retrieved 2026-08-12. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2025-46313MEDIUMmacOS Tahoe Logging Data Redaction Flaw
- CVE-2025-59868MEDIUMHCL Traveler for Microsoft Outlook Sensitive Data Exposure
- CVE-2026-0267MEDIUMPalo Alto GlobalProtect macOS Passcode Exposure Vulnerability
- CVE-2026-11819MEDIUMAnsible keyring_info Module Credential Disclosure Vulnerability
- CVE-2026-11820MEDIUMAnsible Nexmo Module Exposes API Credentials in Logs
- CVE-2026-12086MEDIUMIBM UrbanCode Deploy & DevOps Deploy Information Disclosure via Log Files
- CVE-2026-13750MEDIUMSnowflake CLI Plaintext Credential Leakage in Debug Logs
- CVE-2026-41184MEDIUMCalico ServiceAccount Token Exposure in CNI Logs