Dell PowerProtect Data Manager Improper Verification of Communication Source Vulnerability in REST API

Vulnerability

A vulnerability exists in Dell PowerProtect Data Manager versions prior to 19.22, allowing high-privileged attackers with remote access to exploit improper verification of the communication channel source in the REST API. This could lead to bypassing protection mechanisms.

Impact

Exploitation of this vulnerability could allow an attacker to bypass security mechanisms, potentially leading to unauthorized actions or access within the application.

Remediation

Users can upgrade to Dell PowerProtect Data Manager version 19.22.0-24 or later. For more information, visit the Dell PowerProtect Data Manager Drivers & Downloads page.

Added: Feb 19, 2026, 7:09 PM
Updated: Feb 19, 2026, 7:09 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
3.1
exploitability
4.4
remediation
7.7
relevance
3.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.