CVE-2026-26355: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26355?
CVE-2026-26355 has a medium severity score of 6.5.
How do I fix CVE-2026-26355?
To fix CVE-2026-26355, update to the latest version of Dell PowerProtect Data Domain as recommended by Dell.
What types of systems are affected by CVE-2026-26355?
CVE-2026-26355 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and various LTS release versions.
What is the risk associated with CVE-2026-26355?
CVE-2026-26355 poses a risk of OS command injection, potentially allowing unauthorized command execution.
When was CVE-2026-26355 published?
CVE-2026-26355 was published on July 3, 2026.