CVE-2026-23774: OS Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23774?
CVE-2026-23774 is classified as a high severity OS command injection vulnerability.
How do I fix CVE-2026-23774?
To mitigate CVE-2026-23774, it is recommended to apply the latest security updates provided by Dell for affected versions of PowerProtect Data Domain.
Which versions are affected by CVE-2026-23774?
CVE-2026-23774 affects Dell PowerProtect Data Domain DD OS versions from 7.7.1.0 to 8.5, as well as LTS release versions 8.3.1.0 to 8.3.1.10 and 7.13.1.0 to 7.13.1.40.
Can CVE-2026-23774 be exploited remotely?
Yes, CVE-2026-23774 can potentially be exploited remotely by high privileged attackers.
Is there a workaround for CVE-2026-23774?
At this time, the best approach is to apply security updates as there are no specific workarounds for CVE-2026-23774.