CVE-2026-24506: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24506?
CVE-2026-24506 is classified as a high severity OS command injection vulnerability in Dell PowerProtect Data Domain.
How do I fix CVE-2026-24506?
To fix CVE-2026-24506, Dell recommends updating your PowerProtect Data Domain to the latest version that addresses this vulnerability.
Who can exploit CVE-2026-24506?
CVE-2026-24506 can be exploited by a high privileged attacker with remote access to the affected Dell PowerProtect Data Domain systems.
What versions of Dell PowerProtect Data Domain are affected by CVE-2026-24506?
CVE-2026-24506 affects Dell PowerProtect Data Domain versions from 7.7.1.0 to 8.6, and specific LTS versions including 8.3.1.0 to 8.3.1.20 and 7.13.1.0 to 7.13.1.60.
What type of vulnerability is CVE-2026-24506?
CVE-2026-24506 is an OS command injection vulnerability that allows an attacker to execute arbitrary commands on the affected system.