CVE-2026-23775: High severity Dell PowerProtect Data Domain (DD OS) vulnerability
Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to credential exposures. Authentication attempts as the compromised user would need to be authorized by a high privileged DD user. This vulnerability only affects systems with retention lock enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23775?
The severity of CVE-2026-23775 is classified as low.
How do I fix CVE-2026-23775?
To mitigate CVE-2026-23775, upgrade the Dell PowerProtect Data Domain appliances to the latest version of the DD OS beyond the vulnerable releases.
Who is affected by CVE-2026-23775?
CVE-2026-23775 affects Dell PowerProtect Data Domain appliances running DD OS versions 8.0 to 8.5 and 8.3.1.0 to 8.3.1.10.
What type of vulnerability is CVE-2026-23775?
CVE-2026-23775 is an insertion of sensitive information into log file vulnerability.
Can a low privileged attacker exploit CVE-2026-23775?
Yes, a low privileged attacker with remote access can exploit CVE-2026-23775.