CVE-2026-26942: OS Command Injection
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26942?
CVE-2026-26942 is rated as a high severity vulnerability due to its potential for arbitrary command execution by a high privileged attacker.
How can I fix CVE-2026-26942?
To fix CVE-2026-26942, it is recommended to update Dell PowerProtect Data Domain to version 8.6 or later.
What are the affected versions in CVE-2026-26942?
CVE-2026-26942 affects Dell PowerProtect Data Domain versions from 8.5 to 8.6.
Who can exploit CVE-2026-26942?
A high privileged attacker with remote access can exploit CVE-2026-26942.
What type of vulnerability is CVE-2026-26942?
CVE-2026-26942 is an OS command injection vulnerability due to improper neutralization of special elements.