CVE-2026-28263: XSS
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a cross-site Scripting vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28263?
CVE-2026-28263 has been classified as a high severity cross-site scripting vulnerability.
How do I fix CVE-2026-28263?
To fix CVE-2026-28263, update your Dell PowerProtect Data Domain to the latest versions that address this vulnerability.
What versions are affected by CVE-2026-28263?
CVE-2026-28263 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.5, 8.3.1.0 through 8.3.1.20, and 7.13.1.0 through 7.13.1.50.
Who can exploit CVE-2026-28263?
CVE-2026-28263 can be exploited by a high privileged attacker with access to the affected systems.
What impact does CVE-2026-28263 have on systems?
CVE-2026-28263 can lead to unauthorized access and potentially allow attackers to execute malicious scripts in users' browsers.