PatchSiren

Dell CVE debriefs · Page 6

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Dell CVE published 2026-07-10

CVE-2026-56690

CVE-2026-56690 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure, information exposure, and unauthorized access. This vulnerability has a CVSS score of 8.5 and a severity rating of HIGH. Organizations should prioritize patching this vulnerability [truncated]

HIGH Dell CVE published 2026-07-10

CVE-2026-56689

CVE-2026-56689 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to information exposure. The vulnerability has a CVSS score of 7.7 and a CVSS severity of HIGH. The CVE record was published on 2026-07-10T12:17:23.577Z and has not been modified since then.

MEDIUM Dell CVE published 2026-07-10

CVE-2026-54468

A low privileged attacker with remote access could potentially exploit the path traversal vulnerability in Dell Unisphere for PowerMax, versions 10.3.0.5 and prior, to read arbitrary files. This vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. Security teams and administrators responsible for Dell Unisphere for PowerMax systems should review and apply necessary patches. The vulnerabi [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-56086

CVE-2026-56086 is an Incorrect Authorization vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulne [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-53482

CVE-2026-53482 describes an Integer overflow or wraparound vulnerability in Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of s [truncated]

LOW Dell CVE published 2026-07-08

CVE-2026-53480

CVE-2026-53480 is a path traversal vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification. The vulnerability has a CVSS score of 2.7 and a CVSS severity of LOW. System administrators and security teams should be aware of this vulnerability and take ne [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-41122

CVE-2026-41122 is a stored cross-site scripting vulnerability in Dell PowerProtect Data Domain. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure, session theft, or client-side request forgery. The vulnerability affects multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.7, LTS2026 release ver [truncated]

HIGH Dell CVE published 2026-07-07

CVE-2026-53479

CVE-2026-53479 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A remote high privileged attacker could exploit this vulnerability, leading to protection mechanism bypass. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release vers [truncated]

CRITICAL Dell CVE published 2026-07-07

CVE-2026-53483

CVE-2026-53483 is a critical severity vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerabil [truncated]

CRITICAL Dell CVE published 2026-07-07

CVE-2026-53481

CVE-2026-53481 is a critical severity Path Traversal vulnerability in Dell PowerProtect Data Domain. An unauthenticated attacker with remote access could exploit this vulnerability, leading to unauthorized access to the system. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3. [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-53478

CVE-2026-53478 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to command execution. The vulnerability affects multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-49815

CVE-2026-49815 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to execution of arbitrary OS commands. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and L [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-49814

CVE-2026-49814 is an OS Command Injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to arbitrary command execution. This vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 rel [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-49813

CVE-2026-49813 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with local access could exploit this vulnerability, leading to arbitrary command execution. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 relea [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-46466

A high privileged attacker with remote access could potentially exploit this vulnerability in Dell PowerProtect Data Domain, leading to information tampering. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. This i [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46465

A high privileged attacker with remote access could potentially exploit the use of externally-controlled format string vulnerability in Dell PowerProtect Data Domain, leading to Information disclosure and denial of service. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30 [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46464

A high privileged attacker with remote access could potentially exploit the improper link resolution before file access vulnerability in Dell PowerProtect Data Domain, leading to information disclosure. This vulnerability exists in versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46463

CVE-2026-46463: Dell PowerProtect Data Domain Vulnerability Debrief. Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70, contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-56085

A low privileged attacker with local access could potentially exploit the use of uninitialized resource vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to information exposure. This vulnerability is caused by the use [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-54483

CVE-2026-54483 is an OS command injection vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A high privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. The vulnerabil [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46730

CVE-2026-46730 is an incorrect authorization vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46468

A high privileged attacker with local access could potentially exploit the link following vulnerability in Dell PowerProtect Data Domain, leading to information exposure. This vulnerability affects Dell PowerProtect Data Domain systems, particularly versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46467

A low privileged attacker with local access could potentially exploit this vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to information exposure. This vulnerability is an insertion of sensitive information into log [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-44269

A high privileged attacker with local access could potentially exploit this improper link resolution before file access ('link following') vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to unauthorized access. The vu [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-44268

CVE-2026-44268 is an incorrect permission assignment for a critical resource vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerability exists in multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-41124

A high privileged attacker with local access could potentially exploit the path traversal vulnerability in Dell PowerProtect Data Domain, leading to information exposure. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13. [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-41123

A low privileged attacker with remote access could potentially exploit the improper access control vulnerability in Dell PowerProtect Data Domain, leading to information tampering. This vulnerability affects multiple versions of Dell PowerProtect Data Domain and has a CVSS score of 4.3, indicating a medium severity. The vulnerability is related to an improper access control in the RBAC. System administrat [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-26355

CVE-2026-26355 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to command execution. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versio [truncated]

HIGH Dell CVE published 2026-06-25

CVE-2026-46735

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3 are vulnerable to an OS Command Injection vulnerability. A low-privileged attacker with local access could exploit this vulnerability, potentially leading to command execution. The vulnerability has a high impact due to its local attack vector. Evidence is limited, and defenders should verify affected scope and vendor guidance. Dell Disp [truncated]

HIGH Dell CVE published 2026-06-25

CVE-2026-46733

CVE-2026-46733 is an Improper Access Control vulnerability in Dell Display and Peripheral Manager (DDPM Windows) versions prior to 2.3. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to code execution. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Dell has provided a vendor advisory for mitigation. Users should review and a [truncated]