CVE-2026-44269: Medium severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 8.6.1.10 - Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 8.3.1.30 - Upgrade
Upgrade
Dell PowerProtect Data Domainto a version that resolves this vulnerability.Fixed in 7.13.1.70
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44269?
The severity of CVE-2026-44269 is medium, with a CVSS score of 4.4.
How do I fix CVE-2026-44269?
To fix CVE-2026-44269, update Dell PowerProtect Data Domain to the patched versions as recommended by Dell.
What affected versions are impacted by CVE-2026-44269?
CVE-2026-44269 affects Dell PowerProtect Data Domain versions from 7.7.1.0 through 8.6 and specific LTS release versions.
What type of vulnerability is CVE-2026-44269?
CVE-2026-44269 is an improper link resolution before file access vulnerability.
Is CVE-2026-44269 exploitable remotely?
Yes, CVE-2026-44269 is considered to have a low attack vector as it allows attack through remote exploitation.