CVE-2026-35072: OS Command Injection
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of special elements used in an OS command ('OS command injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Domain Feature Releaseto a version that resolves this vulnerability.Fixed in 8.6.0.0 - Upgrade
Upgrade
Dell PowerProtect Data Domain Feature Releaseto a version that resolves this vulnerability.Fixed in 8.7.0.0 - Upgrade
Upgrade
Dell PowerProtect Data Domain LTS2025 releaseto a version that resolves this vulnerability.Fixed in 8.3.1.20 - Upgrade
Upgrade
Dell PowerProtect Data Domain LTS2024 releaseto a version that resolves this vulnerability.Fixed in 7.13.1.60
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35072?
CVE-2026-35072 is classified as a high severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2026-35072?
To mitigate CVE-2026-35072, update your Dell PowerProtect Data Domain to the latest version released by Dell.
Which versions are affected by CVE-2026-35072?
CVE-2026-35072 affects Dell PowerProtect Data Domain versions 7.7.1.0 to 8.7.0.0, as well as LTS2025 versions 8.3.1.0 to 8.3.1.20 and LTS2024 versions 7.13.1.0 to 7.13.1.60.
What types of attacks can exploit CVE-2026-35072?
CVE-2026-35072 can be exploited through OS command injection attacks, allowing attackers to execute arbitrary commands on the affected system.
Is there a workaround for CVE-2026-35072 if I cannot update immediately?
Currently, there is no official workaround for CVE-2026-35072, so it's advisable to apply the security updates as soon as possible.