TROYANOSYVIRUS
Back to CVEs

CVE-2026-23778

HIGH
7.2

Description

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to gain root-level access.

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published4/17/2026
Last Modified4/20/2026
Sourcenvd
Honeypot Sightings0

Affected Products

dell:data_domain_operating_systemdell:powerprotect_dp_series_appliance

Weaknesses (CWE)

CWE-77

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.