CVE-2026-23778: Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to gain root-level access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23778?
CVE-2026-23778 is classified as a high severity vulnerability due to the potential for command injection by a high privileged attacker.
How do I fix CVE-2026-23778?
To fix CVE-2026-23778, users should update their Dell PowerProtect Data Domain systems to the latest versions that address this vulnerability.
What systems are affected by CVE-2026-23778?
CVE-2026-23778 affects Dell PowerProtect Data Domain systems running versions from 7.7.1.0 to 8.5, as well as specific 8.3.1.0 to 8.3.1.20 and 7.13.1.0 to 7.13.1.50 releases.
What type of vulnerability is CVE-2026-23778?
CVE-2026-23778 is identified as a command injection vulnerability that allows for unauthorized command execution.
Who is at risk from CVE-2026-23778?
Organizations using affected versions of Dell PowerProtect Data Domain systems may be at risk if high privileged attackers exploit the command injection vulnerability.