CVE-2026-26943: OS Command Injection
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an OS command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26943?
CVE-2026-26943 has a high severity level due to the potential for OS command injection by a privileged attacker.
How do I fix CVE-2026-26943?
To fix CVE-2026-26943, upgrade to the latest patched version of Dell PowerProtect Data Domain as recommended by the vendor.
Which versions are affected by CVE-2026-26943?
CVE-2026-26943 affects Dell PowerProtect Data Domain versions from 7.7.1.0 through 8.6 and various LTS release versions.
What type of vulnerability is CVE-2026-26943?
CVE-2026-26943 is classified as an OS command injection vulnerability.
Can CVE-2026-26943 be exploited remotely?
Yes, CVE-2026-26943 can be exploited remotely by an attacker with high privileges.