Dell PowerProtect Data Domain Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Dell PowerProtect Data Domain. This issue affects versions 7.7.1.0 prior to 8.7, LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. The vulnerability allows an unauthenticated attacker with remote access to inject malicious scripts, which could be executed in the context of the user's browser. Exploitation of this vulnerability may lead to information disclosure, session theft, or client-side request forgery.

Impact

Exploitation of this vulnerability could result in stored cross-site scripting, allowing injected scripts to be executed in the context of the user.

Remediation

Users are advised to upgrade to version 8.7.0.0 or later, version 8.8.0.0 or later, or version 7.13.1.80 or later, depending on their current version. For instructions on how to upgrade, see the Dell PowerProtect Data Domain Upgrade Guide.

Added: Jul 8, 2026, 2:48 PM
Updated: Jul 8, 2026, 2:48 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.7
exploitability
6.0
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.