CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
Other sources
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell RecoverPoint for Virtual Machines (RP4VMs)to a version that resolves this vulnerability.Fixed in 6.0.3.1 HF1 - Compensating control
Apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services; discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22769?
CVE-2026-22769 is considered critical due to the presence of hardcoded credentials that can be exploited by unauthenticated remote attackers.
How do I fix CVE-2026-22769?
To fix CVE-2026-22769, upgrade Dell RecoverPoint for Virtual Machines to version 6.0.3.1 HF1 or later.
What versions of Dell RecoverPoint for Virtual Machines are affected by CVE-2026-22769?
CVE-2026-22769 affects all versions of Dell RecoverPoint for Virtual Machines prior to 6.0.3.1 HF1.
What type of vulnerability is CVE-2026-22769?
CVE-2026-22769 is classified as a hardcoded credential vulnerability.
What are the potential risks of CVE-2026-22769 exploitation?
Exploitation of CVE-2026-22769 could lead to unauthorized access to the system, compromising data and operations.