Dell PowerProtect Data Domain Incorrect Authorization Vulnerability Allowing Unauthorized Access

Vulnerability

An incorrect authorization vulnerability has been identified in Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, as well as in LTS2026 release versions 8.6.1.0 through 8.6.1.10, LTS2025 release versions 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. This vulnerability allows a low privileged attacker with remote access to gain unauthorized access to the system.

Impact

Exploitation of this vulnerability could lead to unauthorized access on the affected system.

Remediation

Users are advised to upgrade to version 8.7.0.0 or later, version 8.8.0.0 or later, or version 7.13.1.80 or later, depending on their current version. For instructions on how to upgrade, see the Dell PowerProtect Data Domain Upgrade Guide.

Added: Jul 8, 2026, 2:44 PM
Updated: Jul 8, 2026, 2:44 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.3
exploitability
4.9
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.