CVE-2026-35153: Medium severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, and LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of argument delimiters in a command ('argument injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35153?
CVE-2026-35153 has been classified with a high severity due to its potential for command injection.
How do I fix CVE-2026-35153?
To fix CVE-2026-35153, update your Dell PowerProtect Data Domain software to the latest patched version.
Which versions are affected by CVE-2026-35153?
CVE-2026-35153 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7.0.0 and specific LTS2024 and LTS2025 release versions.
What type of vulnerability is CVE-2026-35153?
CVE-2026-35153 is an improper neutralization of argument delimiters in a command, known as an argument injection vulnerability.
Who is impacted by CVE-2026-35153?
Organizations using vulnerable versions of Dell PowerProtect Data Domain are at risk due to CVE-2026-35153.