PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46737 Dell CVE debrief

CVE-2026-46737 is an Improper Input Validation vulnerability in the REST API of Dell PowerProtect Data Manager versions prior to 20.2.0.0. A high-privileged attacker with remote access could exploit this vulnerability, potentially leading to remote code execution. The vulnerability exists due to inadequate validation of input in the REST API, which could allow an attacker to execute arbitrary code. Administrators and users of Dell PowerProtect Data Manager versions prior to 20.2.0.0 should apply the necessary updates to prevent potential remote code execution.

Vendor
Dell
Product
PowerProtect Data Manager
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Administrators and users of Dell PowerProtect Data Manager versions prior to 20.2.0.0 should apply the necessary updates to prevent potential remote code execution. This vulnerability affects operators who manage Dell PowerProtect Data Manager, as well as security teams responsible for vulnerability management. Affected platforms and components should be reviewed for exposure and patched or mitigated accordingly.

Technical summary

The vulnerability exists in the REST API of Dell PowerProtect Data Manager. An attacker with high privileges and remote access could exploit this vulnerability by providing improperly validated input, potentially leading to remote code execution. The CVSS score for this vulnerability is 6.7, indicating a medium severity level. The vulnerability is caused by inadequate input validation in the REST API, which allows an attacker to execute arbitrary code.

Defensive priority

Medium priority due to the potential for remote code execution and the availability of patches.

Recommended defensive actions

  • Apply the latest updates to Dell PowerProtect Data Manager, specifically version 20.2.0.0 or later.
  • Restrict access to the REST API to only necessary personnel.
  • Monitor for any suspicious activity related to the REST API.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-07-22T16:17:24.093Z and was last modified on 2026-07-22T19:17:04.693Z. The NVD entry is currently undergoing analysis. Dell PowerProtect Data Manager versions prior to 20.2.0.0 are affected by an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. Evidence is limited to public sources and may not reflect the full scope of affected systems or potential impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T16:17:24.093Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.