PT-2026-33808 · Dell · Powerprotect Data Domain Appliances

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-35154

CVSS v3.1

6.3

Medium

AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Dell PowerProtect Data Domain appliances, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper privilege management vulnerability in IDRAC. A high privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges to access unauthorized delete operation in IDRAC.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-35154

Affected Products

Powerprotect Data Domain Appliances