CVE-2026-41122: XSS
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41122?
CVE-2026-41122 has a high severity rating of 7.1.
How do I fix CVE-2026-41122?
To mitigate CVE-2026-41122, update your Dell PowerProtect Data Domain software to the latest versions.
What systems are affected by CVE-2026-41122?
CVE-2026-41122 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, and various LTS release versions.
What type of vulnerability is CVE-2026-41122?
CVE-2026-41122 is a stored cross-site scripting (XSS) vulnerability.
Can an attacker exploit CVE-2026-41122 remotely?
Yes, an unauthenticated attacker can exploit CVE-2026-41122 remotely due to its nature as a stored XSS vulnerability.