CVE-2026-23777: Infoleak
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain an exposure of sensitive information to an unauthorized actor vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to information exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23777?
CVE-2026-23777 has been classified with a severity rating that indicates a significant risk of exposure to sensitive information.
How do I fix CVE-2026-23777?
To remediate CVE-2026-23777, upgrade to the latest supported version of the Dell PowerProtect Data Domain software.
Which versions of Dell PowerProtect Data Domain are affected by CVE-2026-23777?
CVE-2026-23777 affects Dell PowerProtect Data Domain versions from 7.7.1.0 to 8.5, 8.3.1.0 to 8.3.1.20, and 7.13.1.0 to 7.13.1.50.
What types of information are at risk due to CVE-2026-23777?
CVE-2026-23777 exposes sensitive information to unauthorized actors, which may include user data and system configurations.
Is there a workaround for CVE-2026-23777?
There is no official workaround for CVE-2026-23777; patching the software is the recommended action to mitigate the risk.