CVE-2026-41124: Path Traversal
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41124?
CVE-2026-41124 has a low severity rating of 2.3.
How do I fix CVE-2026-41124?
To mitigate CVE-2026-41124, update to the latest versions of Dell PowerProtect Data Domain as specified in the vendor's security advisory.
What systems are affected by CVE-2026-41124?
CVE-2026-41124 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, LTS2026 versions 8.6.1.0 through 8.6.1.10, LTS2025 versions 8.3.1.0 through 8.3.1.30, and LTS2024 versions 7.13.1.0 through 7.13.1.70.
What type of vulnerability is CVE-2026-41124?
CVE-2026-41124 is classified as a path traversal vulnerability.
What consequences can result from CVE-2026-41124?
Exploitation of CVE-2026-41124 could potentially allow unauthorized access to files and directories on the affected systems.