PatchSiren cyber security CVE debrief
CVE-2026-46465 Dell CVE debrief
A high privileged attacker with remote access could potentially exploit the use of externally-controlled format string vulnerability in Dell PowerProtect Data Domain, leading to Information disclosure and denial of service. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. The CVSS score is 5.5, indicating a medium severity vulnerability.
- Vendor
- Dell
- Product
- PowerProtect Data Domain
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-03
- Original CVE updated
- 2026-07-08
- Advisory published
- 2026-07-03
- Advisory updated
- 2026-07-08
Who should care
Administrators and users of Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70 should apply patches or mitigations and review system configurations and inventory for affected versions.
Technical summary
The vulnerability exists in Dell PowerProtect Data Domain due to the use of externally-controlled format string. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and denial of service. The affected versions are 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. The CVSS score is 5.5, indicating a medium severity vulnerability.
Defensive priority
Medium priority due to the CVSS score of 5.5 and the potential for information disclosure and denial of service.
Recommended defensive actions
- Apply patches or updates provided by Dell to vulnerable systems
- Restrict access to vulnerable systems to only necessary personnel
- Monitor system logs for potential exploitation attempts
- Implement compensating controls such as network segmentation or access controls
- Verify system configurations and inventory for affected versions
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-03T14:16:30.473Z and was last modified on 2026-07-08T19:32:19.660Z. The NVD entry is currently Analyzed. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. There is a high privileged attacker with remote access who could potentially exploit this vulnerability, leading to Information disclosure and denial of service. Evidence is limited to CVE and NVD details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46465 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46465
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46465 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46465
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.dell.com/support/kbdoc/en-us/000481268/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.