CVE-2026-23776: High severity Dell PowerProtect Data Domain (DD OS) vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23776?
CVE-2026-23776 has been classified as a moderate severity vulnerability due to improper certificate validation.
How do I fix CVE-2026-23776?
To fix CVE-2026-23776, upgrade your Dell PowerProtect Data Domain systems to a version that is not affected by this vulnerability.
Which versions are affected by CVE-2026-23776?
CVE-2026-23776 affects Dell PowerProtect Data Domain with DD OS versions from 7.7.1.0 through 8.5 and specific LTS releases.
What products are impacted by CVE-2026-23776?
The impacted products include Dell PowerProtect Data Domain running DD OS versions 7.7.1.0 to 8.5 and LTS2024 and LTS2025 versions.
Is there a patch available for CVE-2026-23776?
Yes, Dell provides a security update to patch CVE-2026-23776 which can be found on their support site.