Dell PowerProtect Data Domain Path Traversal Vulnerability Allowing Unauthorized File Modification

Vulnerability

A path traversal vulnerability has been identified in Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, as well as in LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. This vulnerability arises from an improper limitation of pathnames, allowing a high-privileged attacker with remote access to potentially exploit the issue and make unauthorized modifications to files.

Impact

Exploitation of this vulnerability could lead to unauthorized file modifications on the affected system.

Remediation

Users are advised to upgrade to version 8.7.0.0 or later, version 8.8.0.0 or later, or version 7.13.1.80 or later, depending on their current version. For instructions on how to upgrade, see the Dell PowerProtect Data Domain Upgrade Guide.

Added: Jul 8, 2026, 2:46 PM
Updated: Jul 8, 2026, 2:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.4
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.