CVE-2026-40712: Input Validation
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Managerto a version that resolves this vulnerability.Fixed in 20.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40712?
CVE-2026-40712 has a critical severity rating of 9.1.
How do I fix CVE-2026-40712?
To fix CVE-2026-40712, update Dell PowerProtect Data Manager to version 20.2.0.0 or later.
What type of vulnerability is CVE-2026-40712?
CVE-2026-40712 is an Improper Input Validation vulnerability found in the REST API.
Who is affected by CVE-2026-40712?
CVE-2026-40712 affects users of Dell PowerProtect Data Manager versions prior to 20.2.0.0.
What can an attacker achieve by exploiting CVE-2026-40712?
An attacker can potentially achieve elevation of privileges through the exploitation of CVE-2026-40712.