CVE-2026-26944: High severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain a missing authentication for critical function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. Exploitation requires an authenticated user to perform a specific action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26944?
CVE-2026-26944 is classified as a critical vulnerability due to its potential for unauthorized remote access.
How do I fix CVE-2026-26944?
To fix CVE-2026-26944, update your Dell PowerProtect Data Domain to the latest version recommended by Dell, which addresses the missing authentication issue.
What are the affected versions of Dell PowerProtect Data Domain for CVE-2026-26944?
The affected versions for CVE-2026-26944 include Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6 and 8.3.1.0 through 8.3.1.20.
Can CVE-2026-26944 be exploited remotely?
Yes, CVE-2026-26944 can be exploited remotely by an unauthenticated attacker.
What are the risks associated with CVE-2026-26944?
The risks of CVE-2026-26944 include potential unauthorized access and control over critical functions of the affected Dell PowerProtect Data Domain systems.