PT-2026-33438 · Dell · Dell Powerprotect Data Domain

Published

2026-04-14

·

Updated

2026-05-08

·

CVE-2026-35074

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7.0.0 Dell PowerProtect Data Domain versions 8.3.1.0 through 8.3.1.20 Dell PowerProtect Data Domain versions 7.13.1.0 through 7.13.1.60
Description Improper neutralization of special elements allows a high privileged attacker with local access to perform OS Command Injection, which is the execution of arbitrary operating system commands via the application. This can lead to arbitrary command execution with root privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-06487
CVE-2026-35074

Affected Products

Dell Powerprotect Data Domain