PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49809 Dell CVE debrief

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. The vulnerability exists due to improper neutralization of special elements used in an SQL command. To mitigate, apply the security update provided by Dell and restrict remote access to the affected system. Regular vulnerability assessments and monitoring for suspicious activity are recommended. This vulnerability may impact the security posture of affected systems, and prompt action is recommended to prevent potential exploitation. Review system configurations and ensure the security update is applied. Verify system configurations, review logs for suspicious activity, and ensure the security update is applied. Additional information may be needed to fully assess the vulnerability.

Vendor
Dell
Product
Power Protect Cyber Recovery
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-02
Advisory published
2026-08-26
Advisory updated
2026-09-02

Who should care

Administrators and users of Dell PowerProtect Cyber Recovery, version 20.2 and prior, should review and apply the security update provided by Dell to prevent potential exploitation of this vulnerability. Security teams and vulnerability management teams should also be aware of the potential impact and take steps to mitigate it. Additionally, operators and platform administrators should review system configurations and ensure the security update is applied. This vulnerability may impact the security posture of affected systems, and prompt action is recommended to prevent potential exploitation.

Technical summary

The vulnerability exists in Dell PowerProtect Cyber Recovery, versions 20.2 and prior, due to improper neutralization of special elements used in an SQL command. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. The vulnerability can be mitigated by applying the security update provided by Dell and restricting remote access to the affected system. Regular vulnerability assessments and monitoring for suspicious activity are also recommended.

Defensive priority

Medium priority due to potential information disclosure

Recommended defensive actions

  • Review and apply the security update provided by Dell
  • Restrict remote access to the affected system
  • Monitor for suspicious activity
  • Perform regular vulnerability assessments
  • Review system configurations and ensure the security update is applied
  • Verify system configurations and review logs for suspicious activity
  • Ensure the security update is applied and verify system configurations

Evidence notes

The CVE record and NVD entry provide details on the SQL injection vulnerability in Dell PowerProtect Cyber Recovery. The vendor advisory from Dell provides additional information on the security update. However, the scope of affected systems, potential impact, and specific defensive measures are not detailed. Defenders should verify system configurations, review logs for suspicious activity, and ensure the security update is applied. Additional information may be needed to fully assess the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49809 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49809

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49809 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49809

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-us/000501456/dsa-2026-370-security-update-for-dell-powerprotect-cyber-recovery-multiple-third-party-component-vulnerabilities

    [email protected] - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.