PT-2026-33436 · Dell · Dell Powerprotect Data Domain

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-35072

CVSS v3.1

6.7

Medium

AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-35072

Affected Products

Dell Powerprotect Data Domain