CVE-2026-23501: OS Command Injection
Published Aug 19, 2026
·Updated
Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Affected Software
1 affected component
Dell RecoverPoint for VMs>=6.0.3<=6.0.3.1
Event History
Aug 19, 2026
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
Exploitation requires a high-privileged attacker who already has remote access to Dell RecoverPoint for VMs.
2
Which versions are identified as affected?
The affected versions listed are Dell RecoverPoint for VMs 6.0.3 and 6.0.3.1.
3
What could successful exploitation allow?
A successful exploit could allow OS command execution, with high impact to confidentiality, integrity, and availability.