CVE-2026-23779: Command Injection
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to gain root-level access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23779?
CVE-2026-23779 is classified as a command injection vulnerability with a high severity rating.
How do I fix CVE-2026-23779?
To address CVE-2026-23779, update your Dell PowerProtect Data Domain operating system to the latest patched version.
Who is affected by CVE-2026-23779?
CVE-2026-23779 affects Dell PowerProtect Data Domain users operating on specific versions of Data Domain Operating System between 7.7.1.0 and 8.5.
What can attackers do with CVE-2026-23779?
An attacker exploiting CVE-2026-23779 can execute arbitrary commands on the affected system due to the command injection vulnerability.
When was CVE-2026-23779 disclosed?
CVE-2026-23779 was disclosed in 2026, highlighting vulnerabilities in multiple Dell PowerProtect Data Domain feature release versions.