CVE-2026-46737: Input Validation
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dell PowerProtect Data Managerto a version that resolves this vulnerability.Fixed in 20.2.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46737?
The severity of CVE-2026-46737 is rated as medium with a base score of 6.7.
How do I fix CVE-2026-46737?
To mitigate CVE-2026-46737, you should upgrade to Dell PowerProtect Data Manager version 20.2.0.0 or later.
What systems are affected by CVE-2026-46737?
CVE-2026-46737 affects all versions of Dell PowerProtect Data Manager prior to 20.2.0.0.
What type of vulnerability is CVE-2026-46737?
CVE-2026-46737 is an Improper Input Validation vulnerability found in the REST API.
What could an attacker achieve by exploiting CVE-2026-46737?
An attacker with high privileges could potentially achieve remote code execution by exploiting CVE-2026-46737.